From 7dedadefe66ac6613ce8e9102e0ac575a63388e5 Mon Sep 17 00:00:00 2001 From: "R. P. Taylor" <1686627+rptaylor@users.noreply.github.com> Date: Fri, 18 Sep 2026 17:25:42 -0700 Subject: [PATCH 1/2] add note (cherry picked from commit 099e6459c9dca569893ffabe43f6c63f70bc6c87) --- docs/apx-security.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/apx-security.md b/docs/apx-security.md index d249eab..f79fd25 100644 --- a/docs/apx-security.md +++ b/docs/apx-security.md @@ -31,7 +31,7 @@ Therefore, HTTPS should only be used in the following situations: - If an alternative caching solution is employed (e.g. a commercial CDN with TLS termination), eliminating the need for conventional caching forward proxy servers. - To host repositories of confidential data, in conjunction with an authorization mechanism as described below. -Note that most commercial object storages support unencrypted HTTP access, as it is a common requirement for CDN edge nodes and reverse proxying. +Note that nearly all commercial object storages support unencrypted HTTP access, as it is a common requirement for CDN edge nodes and reverse proxying. CernVM-FS can also be used to deliver confidential data. For example, if HTTPS is used in combination with client-authentication using an From 8d6d8d13faa457a96b5704b5244c1218ebe40887 Mon Sep 17 00:00:00 2001 From: "R. P. Taylor" <1686627+rptaylor@users.noreply.github.com> Date: Fri, 18 Sep 2026 17:12:39 -0700 Subject: [PATCH 2/2] fix list format --- docs/apx-security.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/docs/apx-security.md b/docs/apx-security.md index f79fd25..ca7cfd7 100644 --- a/docs/apx-security.md +++ b/docs/apx-security.md @@ -27,9 +27,10 @@ CernVM-FS can be operated with HTTPS data transport, but this breaks site-local cacheability, as a forward caching proxy would be considered a MITM attacker in the context of a HTTPS connection to a stratum server. Therefore, HTTPS should only be used in the following situations: -- If it is necessary to preserve the confidentiality of client data access (i.e. concealing which clients are accessing which files - even though the files may be public). -- If an alternative caching solution is employed (e.g. a commercial CDN with TLS termination), eliminating the need for conventional caching forward proxy servers. -- To host repositories of confidential data, in conjunction with an authorization mechanism as described below. + +- If it is necessary to preserve the confidentiality of client data access (i.e. concealing which clients are accessing which files - even though the files may be public). +- If an alternative caching solution is employed (e.g. a commercial CDN with TLS termination), eliminating the need for conventional caching forward proxy servers. +- To host repositories of confidential data, in conjunction with an authorization mechanism as described below. Note that nearly all commercial object storages support unencrypted HTTP access, as it is a common requirement for CDN edge nodes and reverse proxying.