3 ms·
I use Cloudflare to get HTTPS on my github pages site, and I really like it. I get a lot of control over cached content and security, and statistics about site
by sinistersnare 8y ago
I use Cloudflare to get HTTPS on my github pages site, and I really like it. I get a lot of control over cached content and security, and statistics about site traffic. I am kind of happy that GitHub did not support HTTPS for custom domains, because then I would not have learned how to use Cloudflare.
- minimaxir 8y agoI use Cloudflare on my GitHub pages site, but never saw a HTTPS option. How do you enable that? (and now with GitHub providing certs, is it a better idea to use theirs?)
- aaomidi 8y agoCloudflare's dynamic https would add https on the USER->Cloudflare side of communications.
- bad_user 8y agoCloudflare's HTTPS certificate is shared, which means that your website will share it with other dubious websites. I'm looking at a website on which I have Cloudflare enabled and my certificate is being shared with about 24 other domains. For somebody that knows what HTTPS is about and what it protects against, that's not acceptable. We only accepted it because we find it as being a reasonable compromise given the alternative. So why isn't Cloudflare generating Lets Encrypt certificates, instead of these shared ones? Given their fast response in pursuing other endeavors, my guess is that they need incentives for people to move to their business plans. Therefore I'm glad that GitHub Pages can have HTTPS enabled for custom domains. It means I can now turn off CloudFlare. I'm so glad in fact that I started paying GitHub for a $7 account, even though I don't currently have a need for private repos.
- dannyw 8y agoWhat exactly is the problem? Amazon does the same as well, I believe. The private keys are never given to you, or other sites. It is all within Cloudflare’s edge.
- manigandham 8y agoWhat's unacceptable? There's nothing insecure about sharing a certificate among multiple hostnames. Also you can get a dedicated certificate on the free plan for $5/month.
- bad_user 8y ago$5/month is $60/year, which is ridiculous. I maintain 5 websites hosted on 5 different domains (blog in English, blog in native language and 3 project websites). The cost of 5 certificates would be $300 per year, or $25 per month. Right now I'm paying $0 for the certificates of those 5 domains, thanks to Lets Encrypt. I've been hosting them myself on a Digital Ocean VPS, with really low maintenance, since the machine is updating itself and the websites get built and deployed via Travis. Now I'm moving them to GitHub Pages and my hosting cost will also be zero.
- manigandham 8y agoThe certificates are already free, Cloudflare offered them long before LetsEncrypt. You seem to want a dedicated certificate which is what costs money, likely because of their scale and existing integrations. There is no improved security with a dedicated certificate. You can also host on github pages while using Cloudflare for the custom domain, which is already the most common setup on github for several years now.
- bad_user 8y agoIf there's nothing wrong with those shared certificates, then CloudFlare wouldn't offer "custom certificates" as a $5/month upgrade. > You can also host on github pages while using Cloudflare for the custom domain, which is already the most common setup on github for several years now. Yes, because GitHub Pages was not offering HTTPS for custom domains. Now they do, so that need is gone.
- manigandham 8y agoYes, because people want more, like having multiple levels of subdomains as the free one only supports a single level. Security is absolutely not an issue with a shared certificate and Cloudflare wouldn't get far as a company if they had an insecure product. Why don't you actually explain what you think is so problematic about sharing a cert?