8 results found
-
Use more secure ciphers by default
When performing a security check for a DXP site on internet.nl the result is that "Your web server does not prefer 'Good' over 'Sufficient' over 'Phase out' ciphers" and "Your web server supports one or more ciphers that have a phase out status, because they are known to be fragile and are at risk of becoming insufficiently secure.".
I suggest that more secure ciphers should be used on all DXP sites by default. The more secure ciphers are referred to as "Modern", "Compatible", and "Legacy" in the cloudflare documentation. https://developers.cloudflare.com/ssl/edge-certificates/additional-options/cipher-suites/recommendations/
1 vote -
Make SSL / TLS Certificate Management Self Service
Provide self service tooling via PaaS Portal to allow customers to manage SSL / TLS certificates for their hostnames directly. This would ensure that customers can update custom certificates at their leisure and discretion
1 vote -
Make Management of WAF (Web Application Firewall) activities Self Service
Provide self service tooling via the PaaS Portal to allow the customer to OPT in to WAF modification, and then provide an interface within the PaaS Portal to make Allow Rules, and Block Rules within the WAF.
1 vote -
Make Hostname Setup/Removal/Modification Self Service
Provide self service tooling via PaaS Portal to allow customers to start and complete, hostname setup at their own pace. Provide Self Service tooling via PaaS Portal to manage the removal of hostnames, and or facilitate the moving of hostnames between customer projects as self service.
1 vote -
Make execution of SQL Scripts Self Service
Provide self service tooling to allow for customers to complete this activity directly. Given the high volume of requests Service Desk processes for this activity it is clear that customers and parters have a desire for this kind of utility in the platform.
1 vote -
Alerting for suspicious traffic spikes
Customers never get alerted to suspicious traffic spikes unless they impact site speed or uptime.
Ability to establish alerting for suspicious attacks, even if they are addressed by cloudflare before they impact site performance.1 vote -
Move ADE envs during migrations to CMS 12
Customers who upgrade CMS versions using Self service (11->12) tooling lose access to ADEs unless they specifically request them to be re-provisioned. They should be moved over as part of the migration process. As a standard all provisioned environments including ADE's should be spun up when a migration is completed.
1 vote -
HSTS on the root domain
We are experiencing some redirection issues we have no control over as they are done in the root domain.
http://oldsite.com redirects to https://www.oldsite.com then finally to https://www.newsite.com
The redirection should be as follows:
http://oldsite.com -> https://oldsite.com -> https://www.newsite.com
Please update Optimzely’s configuration to do these redirects properly
1 vote
- Don't see your idea?