Strict-Transport-Security header
Rick O'Sullivan <[email protected]> Tue, 7 Jan 2020 19:35:05 -0500
| Newsgroups | gmane.comp.web.pound.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============1275875274848452122== Content-Type: multipart/alternative; boundary="------------B55C5DF93D935234FD30FB47" Content-Language: en-US This is a multi-part message in MIME format. --------------B55C5DF93D935234FD30FB47 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable Frank's patch outputs this header. It does not generate the=20 includeSubDomains|| and/or preload directives. http.c: BIO_printf(cl, "Strict-Transport-Security: max-age=3D%d\r\n",=20 svc->sts); On 1/7/20 3:13 PM, Fathi Ben Nasr wrote: > > Hi, > > What is the resulting header when you add StrictTransportSecurity=20 > <SECONDS> to the config file ? Does it generate the=20 > includeSubDomains|| and/or preload directives ? > > TIA > > Fathi B.N. > > Le 31/12/2019 =C3=A0 19:51, Rick O'Sullivan a =C3=A9crit=C2=A0: >> I've merged Frank's HSTS patch to add the StrictTransportSecurity=20 >> directive into my fork at https://github.com/patrodyne/pound >> >> On 12/30/19 3:13 AM, Frank Schmirler wrote: >>> Am Donnerstag, 26. Dezember 2019 14:57 CET,[email protected]= t schrieb: >>>> Does Pound support HSTS ? >>>> >>>> Does Pound support adding headers to the outgong web response? >>>> I see the "AddHeader" option which apparently adds headers to the >>>> incoming request (to the back-end server), but I don't see any optio= ns >>>> that let me add headers to the outgoing response (back to the client= ). >>> I've attached the HSTS patch I posted years ago (updated to pound 2.8= ). With the patch you can add the following directive to your config at s= ervice level: >>> StrictTransportSecurity <SECONDS> >>> >>> Best regards, >>> Frank >>> >> >> --------------B55C5DF93D935234FD30FB47 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF= -8"> </head> <body> Frank's patch outputs this header. It does not generate the includeSubDomains<code></code> and/or preload directives.<br> <br> http.c: BIO_printf(cl, "Strict-Transport-Security: max-age=3D%d\r\n",= svc->sts);<br> <br> <div class=3D"moz-cite-prefix">On 1/7/20 3:13 PM, Fathi Ben Nasr wrote:<br> </div> <blockquote type=3D"cite" cite=3D"mid:[email protected]= om"> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DU= TF-8"> <p>Hi,</p> <p>What is the resulting header when you add StrictTransportSecurity <SECONDS> to the config file ? Does it generate the includeSubDomains<code></code> and/or preload directives ?</p> <p>TIA</p> <p> Fathi B.N.</p> <div class=3D"moz-cite-prefix">Le 31/12/2019 =C3=A0 19:51, Rick O'Sullivan a =C3=A9crit=C2=A0:<br> </div> <blockquote type=3D"cite" cite=3D"mid:1bb2adce-c94c-dcdb-6192-3da11bfd163f-wX4xtrkQXJPNLxjTenLetw@public.gmane.org"> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF-8"> I've merged Frank's HSTS patch to add the StrictTransportSecurity directive into my fork at <a class=3D"moz-txt-link-freetext" href=3D"https://github.com/patrodyne/pound" moz-do-not-send=3D"true">https://github.com/patrodyne/pound</a>= <br> <br> <div class=3D"moz-cite-prefix">On 12/30/19 3:13 AM, Frank Schmirler wrote:<br> </div> <blockquote type=3D"cite" cite=3D"mid:2b-5e09b180-3-7ae77d00@258145686"> <pre class=3D"moz-quote-pre" wrap=3D"">Am Donnerstag, 26. Dezem= ber 2019 14:57 CET, <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:= [email protected]" moz-do-not-send=3D"true">[email protected]= inux.net</a> schrieb:=20 </pre> <blockquote type=3D"cite"> <pre class=3D"moz-quote-pre" wrap=3D"">Does Pound support HST= S ? Does Pound support adding headers to the outgong web response? I see the "AddHeader" option which apparently adds headers to the incoming request (to the back-end server), but I don't see any options that let me add headers to the outgoing response (back to the client). </pre> </blockquote> <pre class=3D"moz-quote-pre" wrap=3D"">I've attached the HSTS p= atch I posted years ago (updated to pound 2.8). With the patch you can ad= d the following directive to your config at service level: StrictTransportSecurity <SECONDS> Best regards, Frank </pre> <br> <fieldset class=3D"mimeAttachmentHeader"></fieldset> </blockquote> <br> <br> <fieldset class=3D"mimeAttachmentHeader"></fieldset> </blockquote> </blockquote> <br> </body> </html> --------------B55C5DF93D935234FD30FB47-- --===============1275875274848452122== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- pound mailing list [email protected] https://admin.hostpoint.ch/mailman/listinfo/pound_apsis.ch --===============1275875274848452122==--