3 ms·
Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch
by konklone 10y ago
Co-author of the post here, happy to answer questions. =)
This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant:
https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-progress-on-moving-https/ https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...
- tomschlick 10y agoAny plans to force IPv6 adoption in the same manner?
- toomuchtodo 10y agoIPv6 is pretty low priority compared to comprehensive HTTPS support. Disclaimer: Not USDS/18F, just tech professional.
- deleted 10y ago[deleted]
- tomschlick 10y agoOh I agree, but the two things can be done at the same time. Especially for new .gov sites. It appears a lot of .gov sites already support IPv6 but I was wondering if it's an official policy or just at the discretion of the tech team.
- konklone 10y agoIPv6 is a federal mandate for agencies: https://www.whitehouse.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://www.whitehouse.gov/sites/default/files/omb/assets/eg... And NIST has a dashboard of adoption: https://usgv6-deploymon.antd.nist.gov/cgi-bin/generate-gov https://usgv6-deploymon.antd.nist.gov/cgi-bin/generate-gov
- tomschlick 10y agoFantastic! Thanks!
- austincheney 10y agoDoes this include DOD? I suspect DOD is probably already doing this, but just wonder if they fall under the umbrella.
- konklone 10y agoDoD does have some .gov domains, so it would affect them in that way. But .mil is not affected.
- walrus01 10y agoDoD uses https and crypto at the transport layer in SIPR. Lots of "type 1" crypto as well, which is its own special thing with NSA issued hardware crypto keys.
- deleted 10y ago[deleted]
- stqism 10y agoThe DoD has a massive PKI system already and makes the assumption users of its sites have the appropriate CAs installed. (Home access typically requires installing a set of them, typically bundled separately or in an installer)
- scrollaway 10y agoThe blog post is unclear. On a technical level (on the preload list), is the enforcement at the TLD level or is it just a legal requirement to submit all .gov domain names to the preload list? If the latter, any plan to move to the former?
- konklone 10y agoNot quite either one -- it's technical enforcement by the TLD, but still done on a per-domain basis (this doesn't affect state/local .gov domains, or legislative/judicial .gov domains). The dotgov.gov program will forcibly preload new domains, but it's not feasible to just submit ".gov" to the preload list right now.