Inter-Actief / Inter-Actief/Beheer_Issues

Make IA-domains confirm to modern internet standards

Open
#131 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Not all IA domains conform to modern internet standards. It would be great if we would contribute to a safer and more robust internet by adopting modern standards.

The possible improvements are listed here per domain. Also related is #21

### inter-actief.net
**Web** - https://internet.nl/site/inter-actief.net/3857516/ and https://internet.nl/site/www.inter-actief.net/3857517/
- [ ] IPv6 support webserver
- [ ] DNSSEC signing
- [ ] correct HTTPS redirect
- [ ] CAA records
- [ ] HTTP security headers: X-Frame-Options, X-Content-Type-Options, Content-Security-Policy, Referrer-Policy
- [ ] security.txt (redirect should be fixed)

**E-mail** - https://internet.nl/mail/inter-actief.net/1801658/
- [ ] DNSSEC (Also see #130, Google has undocumented DNSSEC-signed mailservers https://blog.rac.me.uk/2022/11/02/dnssec-signed-google-apps-g-suite-email/)
- [ ] DMARC
- [ ] DANE (See #130, no support by Google yet)

**E-mail for www** - https://internet.nl/mail/www.inter-actief.net/1801661/#control-panel-11
- [ ] SPF should be added for the www subdomain (`v=spf1 -all`) to prevent spoofing from @www.inter-actief.net

### inter-actief.nl
**Web** - https://internet.nl/site/inter-actief.nl/3857547/ and https://internet.nl/site/www.inter-actief.nl/3857546/
- [ ] IPv6 support webserver
- [ ] DNSSEC signing
- [ ] correct HTTPS redirect
- [ ] HSTS header
- [ ] CAA records
- [ ] HTTP security headers: X-Frame-Options, X-Content-Type-Options, Content-Security-Policy, Referrer-Policy
- [ ] security.txt (redirect is correct, but file should end with a newline, hence the error)

**E-mail** - https://internet.nl/mail/inter-actief.nl/1801667/
- [ ] DNSSEC (Also see #130, Google has undocumented DNSSEC-signed mailservers https://blog.rac.me.uk/2022/11/02/dnssec-signed-google-apps-g-suite-email/)
- [ ] DMARC
- [ ] DANE (See #130, no support by Google yet)

**E-mail for www** - https://internet.nl/mail/www.inter-actief.nl/1801664/
- [ ] SPF should be added for the www subdomain (`v=spf1 -all`) to prevent spoofing from @www.inter-actief.nl

### inter-actief.utwente.nl
**Web** - https://internet.nl/site/www.inter-actief.utwente.nl/3857562/ & https://internet.nl/site/inter-actief.utwente.nl/3857563/
Same as above

**E-mail** - https://internet.nl/mail/inter-actief.utwente.nl/1801670/# & https://internet.nl/mail/www.inter-actief.utwente.nl/1801672/
Same as above. Note that the DMARC of utwente.nl is currently used, which means that the UT receives aggregates of IA's e-mail behaviour...

Possible other domains used by IA can be checked via https://internet.nl

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked internet.nl reports for inter-actief.net, inter-actief.nl, and inter-actief.utwente.nl, then review related issues #21 and #130. Separate actionable DNS, web-server, email, and security-header items from provider limitations noted in the issue. Done means the applicable checklist items are resolved or explicitly documented as blocked.

Written by the indexing model from the issue text.

Assessment

Domain
infrastructure, networking, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.