【问题标题】:Errors when checking eligibility for HSTS preload检查 HSTS 预加载的资格时出错
【发布时间】:2021-09-09 21:23:24
【问题描述】:

我已经建立了这个网站: http://website1.com/ - 返回301 Moved Permanently 并重定向到http://www.website1.com/

http://www.website1.com/ - 返回301 Moved Permanently 并重定向到https://www.website2.com/

https://www.website2.com/ - 返回200 OK 并在响应中包含:

strict-transport-security: max-age=31536000; includeSubDomains

我有这个运行网络应用程序的子域: https://subdomain.website1.com/ 这在响应中也有以下标头:

Strict-Transport-Security: max-age=31536000; includeSubDomains

我想为 website1.com/ 的所有子域提供预加载功能。 但是,在检查eligibility 时出现以下错误:

Error: No HSTS header
Response error: No HSTS header is present on the response.

Error: HTTP redirects to www first
http://website1.com (HTTP) should immediately redirect to https://website1.com (HTTPS) before adding the www subdomain.
Right now, the first redirect is to http://www.website1.com/.
The extra redirect is required to ensure that any browser which supports HSTS will record the HSTS entry for the top level domain, not just the subdomain.

第一个错误很简单,我只需添加 HSTS 标头即可。

但是为什么有重定向很重要?

我只想让http://subdomain.website1.com/ 内部重定向到https://subdomain.website1.com/,并让http://website1.com/ 内部重定向到https://website1.com/

无论是否重定向到www.website1.com/http://website1.com 都不能进行内部重定向到https://website1.com

【问题讨论】:

    标签: http https hsts


    【解决方案1】:

    我设置了这个网站:http://website1.com/ - 返回 301 Moved Permanently 并重定向到 http://www.website1.com/

    这是你的问题。 http://website1.com 应该重定向到 https://website1.com 然后到 https://www.website1.com

    这样,顶级 website1.com 域将获取 HSTS 标头并保护自己和所有子域(假设它具有 includeSubDomains 属性集 - 这是预加载的先决条件)。

    如果不先切换到 HTTPS,或者直接跳到https://www.website1.com,那么浏览器将永远不会在顶级域上看到 HSTS 标头,因此知道它(以及所有子域)应该受 HSTS 保护。这是 1) 不太安全和 2) 预加载时风险更大,因为您可能仍然有一个非 HTTPS 站点(例如 http://blog.website1.comhttp://intranet.website1.com)。通过强制您在预加载之前进行设置,有望在仍然有可能逆转 HSTS 的情况下出现这些问题(这在预加载到浏览器的源代码后基本上是不可能的 - 至少在几个月内)。

    使用预加载意外锁定非 HTTPS 子域的风险是I’ve argued in the past that preload is potentially more risky than useful 的原因之一,并且对于大多数网站来说都是过度杀伤力。但随着 HTTPS 成为常态,我现在不那么反对它了。不过,除了高目标网站外,仍然认为这有点矫枉过正。

    顺便说一句,对于第一个错误,请确保 HSTS 标头包含在 301 重定向中。例如,对于 Apache,您需要 always set 而不仅仅是 set,如下所述:https://stackoverflow.com/a/48103216/2144578

    【讨论】:

    • 你没说完:“但随着 HTTPS 成为我的常态”
    • 糟糕。现在完成了。
    • 预加载功能是否会使 HSTS 标头变得多余?如果 Chrome 因为预加载而知道使用 HTTPS 而不是 HTTP,那么 HSTS 标头实际上并没有做任何正确的事情?
    • "顺便说一句,对于第一个错误,请确保 HSTS 标头包含在 301 重定向中。" - 但那些重定向使用的是 http。使用 http 时不应该返回 HSTS。
    • 这不是多余的,有两个重要原因:1)不是每个浏览器都支持预加载列表。以 GoogleBot 为例?您是否不在乎是否在搜索中找到您的网页? 2) 预加载列表将检查标题是否存在,并可能将其从您删除的预加载列表中删除。所以是的,对于支持预加载的浏览器,它并没有真正做任何事情,但是不发送它的原因是什么?为了节省区区几个字节?
    猜你喜欢
    • 2021-06-24
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2013-04-16
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多