canada-ca / canada-ca/tracker

Write collection of change requests for Tracker issues and submit to orgs

Open
#4,980 0 comments 0 reactions 1 assignee Assigned to @h701h View on GitHub
Needs Investigation
Dominant language
JavaScript
Stars
39
Forks
15
Avg merge
1d 5h
Merged PRs (30d)
22

Description

In order:

- [ ] TBS
- [ ] SSC SSC Service Delivery Manager
- [ ] TBD

Issue Type: Task
Summary: Upgrade Website to HTTPS

Description:
Upgrade [Insert Website URL] to use HTTPS for improved security and user trust. Currently, the website is accessible via HTTP, which poses potential security risks and may negatively affect our ..........

Details:

Website URL: [Insert Website URL]
Current Status: The website is currently accessible via **HTTP**.
Requested Action: Upgrade the website to use HTTPS as per the Web Sites and Services Management Configuration Requirements, section 1.1 which reads Ensure that all production websites and web services are configured to provide service only through a secure connection that is configured for HTTPS (and redirected from HTTP).
Additional Information:

HTTPS implementation should follow best practices, including:
1.1 Ensure that all production websites and web services are configured to provide service only through a secure connection that is configured for HTTPS (and redirected from HTTP).
1.2 Enable HTTP Strict Transport Security (HSTS).
1.3 Follow the guidance [Recommendations for TLS Server Certificates for GC Public Facing Web Services](https://www.gcpedia.gc.ca/gcwiki/images/8/89/Recommendations_for_TLS_Server_Certificates.pdf) for Transport Layer Security (TLS) server certificates.
1.4 Implement TLS 1.2, or subsequent versions, and use supported cryptographic algorithms and certificates, as outlined in:
1.4.1 [Guidance on Securely Configuring Network Protocols ITSP.40.062, subsection 3.1 AES Cipher Suites](https://cyber.gc.ca/en/guidance/guidance-securely-configuring-network-protocols-itsp40062#a31); and
1.4.2 [Cryptographic Algorithms for Unclassified, Protected A, and Protected B Information (ITSP.40.111)](https://cyber.gc.ca/en/guidance/cryptographic-algorithms-unclassified-protected-and-protected-b-information-itsp40111)
1.4.3 Disable all other cryptographic algorithms.
1.5 Disable known weak protocols such as Secure Sockets Layer (SSL) v2 and v3 and TLS 1.0 and 1.1.
1.6 Disable known weak ciphers (RC4 and 3DES).

Acceptance Criteria:

The website must be accessible via HTTPS with a valid SSL certificate.
All internal and external links and resources on the website should use HTTPS.
HTTP requests should be automatically redirected to HTTPS.
The website should be tested for any mixed content issues or security vulnerabilities.

Due Date: [Insert Due Date]

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.