Comment 9 for bug 1436279

Revision history for this message
Mike Pontillo (mpontillo) wrote :

This really has nothing to do with Apache, though. The fact is that reverse-proxying MAAS using *any* other port will have this problem. We need to remove the "special" data-websocket-port in the HTML and ensure everything flows over a single port, and fix anything that breaks resulting from that.

Respectfully disagree about the severity; I think mixing HTTP and non-HTTPS is a security nightmare waiting to happen. Don't we send BMC credentials over the websocket already? What about other sensitive data like cookies and/or authentication tokens? With 1.9+ I expect the severity will increase as more data flows over websockets.