<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>dubovsky.com rantings &#187; Site</title>
	<atom:link href="http://www.dubovsky.com/rantings/category/site/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dubovsky.com/rantings</link>
	<description>Yet another web log of personal junk.</description>
	<lastBuildDate>Thu, 06 May 2010 18:56:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CAcert.org &#8211; free community-based SSL certificates</title>
		<link>http://www.dubovsky.com/rantings/2006/04/30/cacertorg-free-community-based-ssl-certificates/</link>
		<comments>http://www.dubovsky.com/rantings/2006/04/30/cacertorg-free-community-based-ssl-certificates/#comments</comments>
		<pubDate>Mon, 01 May 2006 01:16:13 +0000</pubDate>
		<dc:creator>jon</dc:creator>
				<category><![CDATA[Activism]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Site]]></category>

		<guid isPermaLink="false">http://www.dubovsky.com/rantings/2006/04/30/cacertorg-free-community-based-ssl-certificates/</guid>
		<description><![CDATA[SSL certificates for a web site are pretty cheap, as is SSL-capable web hosting.  However, for development reasons, I need a wildcard certificate and refuse to pay the several hundred dollars (annual) fee to a commercial CA to get one.
Long story short: if you&#8217;re trying to log in here (so you can post and [...]]]></description>
			<content:encoded><![CDATA[<p>SSL certificates for a web site are pretty cheap, as is <acronym>SSL</acronym>-capable web hosting.  However, for development reasons, I need a wildcard certificate and refuse to pay the several hundred dollars (annual) fee to a commercial <acronym>CA</acronym> to get one.</p>
<p>Long story short: if you&#8217;re trying to log in here (so you can post and such), your browser is probably warning you that my <acronym>SSL</acronym> certificate isn&#8217;t signed by a Certificate Authority that the browser knows.  If you wish to solve this and help support <a href="http://www.cacert.org/">a free community-based CA (CAcert.org)</a>, read on.  If not, you can skip this.</p>
<p>To import the CAcert&#8217;s Root Certificate (allowing you to determine if CAcert&#8217;s customer certificates are valid or not), please visit their <a href="http://www.cacert.org/index.php?id=3">root certificate page</a>.  </p>
<p><span id="more-17"></span></p>
<p>In case you wish one more data point to verify the certificates, here are their fingerprints as I see them:</p>
<ul>
<li>Class 1 root certificate (the important one)
<ul>
<li><em><acronym>SHA1</acronym></em>: <code>13:5C:EC:36:F4:9C: B8:E9:3B:1A:B2:70: CD:80:88:46:76:CE: 8F:33</code></li>
<li><em><acronym>MD5</acronym></em>: <code>A6:1B:37:5E:39:0D: 9C:36:54:EE:BD:20: 31:46:1F:6B</code></li>
</ul>
</li>
<li>Class 3 root certificate
<ul>
<li><em><acronym>SHA1</acronym></em>: <code>DB:4C:42:69:07:3F: E9:C2:A3:7D:89:0A: 5C:1B:18:C4:18:4E: 2A:2D</code></li>
<li><em><acronym>MD5</acronym></em>: <code>73:3F:35:54:1D:44: C9:E9:5A:4A:EF:51: AD:03:06:B6</code></li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.dubovsky.com/rantings/2006/04/30/cacertorg-free-community-based-ssl-certificates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thanks to Diann</title>
		<link>http://www.dubovsky.com/rantings/2006/04/09/thanks-to-diann/</link>
		<comments>http://www.dubovsky.com/rantings/2006/04/09/thanks-to-diann/#comments</comments>
		<pubDate>Mon, 10 Apr 2006 02:35:58 +0000</pubDate>
		<dc:creator>jon</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Site]]></category>

		<guid isPermaLink="false">http://www.dubovsky.com/rantings/2006/04/09/thanks-to-diann/</guid>
		<description><![CDATA[I&#8217;ve been meaning to post a few words of thanks to Diann here and properly give her credit for (among things too numerous to count) a lot of my site design ideas and motivation.  She was the one who turned me on to div-based layouts, accessibility issues, and a host of other interesting matters. [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been meaning to post a few words of thanks to <a href="http://www.everwild.net/">Diann</a> here and properly give her credit for (among things too numerous to count) a lot of my site design ideas and motivation.  She was the one who turned me on to div-based layouts, accessibility issues, and a host of other interesting matters.  I teach her PHP and she teaches me CSS; quite the team!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dubovsky.com/rantings/2006/04/09/thanks-to-diann/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress secure (SSL / HTTPS) administration hack</title>
		<link>http://www.dubovsky.com/rantings/2006/04/01/wordpress-secure-ssl-https-administration-hack/</link>
		<comments>http://www.dubovsky.com/rantings/2006/04/01/wordpress-secure-ssl-https-administration-hack/#comments</comments>
		<pubDate>Sat, 01 Apr 2006 16:02:32 +0000</pubDate>
		<dc:creator>jon</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Site]]></category>

		<guid isPermaLink="false">http://www.dubovsky.com/rantings/2006/04/01/wordpress-secure-ssl-https-administration-hack/</guid>
		<description><![CDATA[I discovered that WordPress doesn&#8217;t support outputting secure (HTTPS) links for the login, admin, and registration pages.  SSL seeems to be an all-or-nothing thing for them.  It also doesn&#8217;t provide a way to limit your session cookies being only sent over a secure link.  Since I do all my editing over secure [...]]]></description>
			<content:encoded><![CDATA[<p>I discovered that WordPress doesn&#8217;t support outputting secure (HTTPS) links for the login, admin, and registration pages.  SSL seeems to be an all-or-nothing thing for them.  It also doesn&#8217;t provide a way to limit your session cookies being <i>only</i> sent over a secure link.  Since I do all my editing over secure links (there is customer data on this site!), this irked me a bit, so I looked for ways to work around it.</p>
<p>J&uuml;rgen Kreileder has a <a href="http://blog.blackdown.de/2006/01/22/securing-wordpress-2-admin-access-with-ssl/">great blog entry on how to hack Wordpress to use secure administration pages</a>.  Alas, it does more than I want (comment spam management) and my web server doesn&#8217;t run the mod_proxy required to complete the URL output rewriting.  I had to do something a bit more&#8230; sinister (read: hackish).</p>
<p>Theory:</p>
<ul>
<li><a id="p9" href="/rantings/wp-content/uploads/2006/04/wordpress_ssl.patch.txt" title="Wordpress 2.02 patch for partially enabling SSL links to sensitive pages (part 1 of 3, patch file)">use part of Kreileder&#8217;s hack</a> (see above) for ensuring the cookies are secure, the auth_redirect goes to a secure page, the admin_referrer check is for a secure page, and chuck the rest of it.</li>
<li>replace the mod_proxy output link rewriting with an <a id="p10" href="http://www.dubovsky.com/rantings/wp-content/uploads/2006/04/wordpress_ssl.config.txt" title="Wordpress 2.02 patch for partially enabling SSL links to sensitive pages (part 2 of 3, wp-config.php)">extremely hackish change to wp-config.php</a> (the only file of which I&#8217;m aware that is included in every other page), buffering the output of the page via PHP&#8217;s ob_start and then going through and rewriting and &#8220;http://&#8221; links to sensitive pages with &#8220;https://&#8221; links.  (I&#8217;m going to programmer&#8217;s hell for this.)</li>
<li>a <a id="p11" href="/rantings/wp-content/uploads/2006/04/wordpress_ssl.htaccess.txt" title="Wordpress 2.02 patch for partially enabling SSL links to sensitive pages (part 3 of 3, .htaccess)">fairly simple .htaccess rewrite block</a> to redirect insecure access to sensitive pages to their secure versions</li>
</ul>
<p>It&#8217;s not pretty, but it works.  Caveat emptor!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dubovsky.com/rantings/2006/04/01/wordpress-secure-ssl-https-administration-hack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New blog software; same slow content.</title>
		<link>http://www.dubovsky.com/rantings/2006/03/27/new-blog-software-same-slow-content/</link>
		<comments>http://www.dubovsky.com/rantings/2006/03/27/new-blog-software-same-slow-content/#comments</comments>
		<pubDate>Mon, 27 Mar 2006 22:18:39 +0000</pubDate>
		<dc:creator>jon</dc:creator>
				<category><![CDATA[Site]]></category>

		<guid isPermaLink="false">http://www.dubovsky.com/blog/2006/03/27/new-blog-software-same-slow-content/</guid>
		<description><![CDATA[I&#8217;ve switched over to WordPress for keeping up the Rantings page here.  I&#8217;ll be messing around with settings for a few days, but please email me if you see anything strange.  Expect this place to be thin on content for a bit until I get the setup down.
The old rantings are still available.
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve switched over to WordPress for keeping up the Rantings page here.  I&#8217;ll be messing around with settings for a few days, but please email me if you see anything strange.  Expect this place to be thin on content for a bit until I get the setup down.</p>
<p>The <a href="/old-rantings/">old rantings</a> are still available.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dubovsky.com/rantings/2006/03/27/new-blog-software-same-slow-content/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
