[13:11:35] 10HTTPS, 10Traffic, 10Operations, 10WMF-Communications, 10Security-Other: Server certificate is classified as invalid on government computers - https://phabricator.wikimedia.org/T128182#3717641 (10Florian) @BBlack Nevertheless: Thanks for your time and work you put into this! :) [16:07:13] 10Traffic, 10ORES, 10Operations, 10Scoring-platform-team, and 4 others: 503 spikes and resulting API slowness starting 18:45 October 26 - https://phabricator.wikimedia.org/T179156#3717711 (10hoo) Happening again, this time on `cp1055`. Example from `mw1180`: ``` $ ss --tcp -r | grep -oP 'cp\d+' | sort |... [16:14:13] 10Traffic, 10ORES, 10Operations, 10Scoring-platform-team, and 4 others: 503 spikes and resulting API slowness starting 18:45 October 26 - https://phabricator.wikimedia.org/T179156#3717712 (10hoo) Also on `mw1180`: ``` $ sudo -u www-data ss --tcp -r -p > ss $ cat ss | grep -c FIN-WAIT-2 16 $ cat ss | grep... [16:23:01] 10Traffic, 10ORES, 10Operations, 10Scoring-platform-team, and 4 others: 503 spikes and resulting API slowness starting 18:45 October 26 - https://phabricator.wikimedia.org/T179156#3717713 (10Paladox) p:05Triage>03Unbreak! Spoke to hoo on irc, who agreed it's an UBN now. [20:21:42] 10Traffic, 10ORES, 10Operations, 10Scoring-platform-team, and 4 others: 503 spikes and resulting API slowness starting 18:45 October 26 - https://phabricator.wikimedia.org/T179156#3717847 (10BBlack) Updates from the Varnish side of things today (since I've been bad about getting commits/logs tagged onto th... [21:44:20] 10HTTPS, 10Traffic, 10Operations: implement Public Key Pinning (HPKP) for Wikimedia domains - https://phabricator.wikimedia.org/T92002#3717886 (10BBlack) 05Open>03declined For all of the same good reasons pointed out a while back in e.g. https://blog.qualys.com/ssllabs/2016/09/06/is-http-public-key-pinni... [22:05:43] 10Traffic, 10ORES, 10Operations, 10Scoring-platform-team, and 4 others: 503 spikes and resulting API slowness starting 18:45 October 26 - https://phabricator.wikimedia.org/T179156#3717895 (10BBlack) A while after the above, @hoo started focusing on a different aspect of this we've been somewhat ignoring as... [23:55:48] 10HTTPS, 10Traffic, 10Operations: implement Public Key Pinning (HPKP) for Wikimedia domains - https://phabricator.wikimedia.org/T92002#1101271 (10Tgr) So are there any plans to implement Certificate Transparency instead, given that it is the replacement suggested by Google?