Strict-Transport-Security header

Rick O'Sullivan <[email protected]> Tue, 7 Jan 2020 19:35:05 -0500
Newsgroups gmane.comp.web.pound.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============1275875274848452122==
Content-Type: multipart/alternative;
 boundary="------------B55C5DF93D935234FD30FB47"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------B55C5DF93D935234FD30FB47
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable

Frank's patch outputs this header. It does not generate the=20
includeSubDomains|| and/or preload directives.

http.c: BIO_printf(cl, "Strict-Transport-Security: max-age=3D%d\r\n",=20
svc->sts);

On 1/7/20 3:13 PM, Fathi Ben Nasr wrote:
>
> Hi,
>
> What is the resulting header when you add StrictTransportSecurity=20
> <SECONDS> to the config file ? Does it generate the=20
> includeSubDomains|| and/or preload directives ?
>
> TIA
>
> Fathi B.N.
>
> Le 31/12/2019 =C3=A0 19:51, Rick O'Sullivan a =C3=A9crit=C2=A0:
>> I've merged Frank's HSTS patch to add the StrictTransportSecurity=20
>> directive into my fork at https://github.com/patrodyne/pound
>>
>> On 12/30/19 3:13 AM, Frank Schmirler wrote:
>>> Am Donnerstag, 26. Dezember 2019 14:57 CET,[email protected]=
t  schrieb:
>>>> Does Pound support HSTS ?
>>>>
>>>> Does Pound support adding headers to the outgong web response?
>>>> I see the "AddHeader" option which apparently adds headers to the
>>>> incoming request (to the back-end server), but I don't see any optio=
ns
>>>> that let me add headers to the outgoing response (back to the client=
).
>>> I've attached the HSTS patch I posted years ago (updated to pound 2.8=
). With the patch you can add the following directive to your config at s=
ervice level:
>>> StrictTransportSecurity <SECONDS>
>>>
>>> Best regards,
>>> Frank
>>>
>>
>>


--------------B55C5DF93D935234FD30FB47
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF=
-8">
  </head>
  <body>
    Frank's patch outputs this header. It does not generate the
    includeSubDomains<code></code> and/or preload directives.<br>
    <br>
    http.c: BIO_printf(cl, "Strict-Transport-Security: max-age=3D%d\r\n",=

    svc-&gt;sts);<br>
    <br>
    <div class=3D"moz-cite-prefix">On 1/7/20 3:13 PM, Fathi Ben Nasr
      wrote:<br>
    </div>
    <blockquote type=3D"cite"
      cite=3D"mid:[email protected]=
om">
      <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DU=
TF-8">
      <p>Hi,</p>
      <p>What is the resulting header when you add
        StrictTransportSecurity &lt;SECONDS&gt; to the config file ?
        Does it generate the includeSubDomains<code></code> and/or
        preload directives ?</p>
      <p>TIA</p>
      <p> Fathi B.N.</p>
      <div class=3D"moz-cite-prefix">Le 31/12/2019 =C3=A0 19:51, Rick
        O'Sullivan a =C3=A9crit=C2=A0:<br>
      </div>
      <blockquote type=3D"cite"
        cite=3D"mid:1bb2adce-c94c-dcdb-6192-3da11bfd163f-wX4xtrkQXJPNLxjTenLetw@public.gmane.org">
        <meta http-equiv=3D"Content-Type" content=3D"text/html;
          charset=3DUTF-8">
        I've merged Frank's HSTS patch to add the
        StrictTransportSecurity directive into my fork at <a
          class=3D"moz-txt-link-freetext"
          href=3D"https://github.com/patrodyne/pound"
          moz-do-not-send=3D"true">https://github.com/patrodyne/pound</a>=
<br>
        <br>
        <div class=3D"moz-cite-prefix">On 12/30/19 3:13 AM, Frank
          Schmirler wrote:<br>
        </div>
        <blockquote type=3D"cite"
          cite=3D"mid:2b-5e09b180-3-7ae77d00@258145686">
          <pre class=3D"moz-quote-pre" wrap=3D"">Am Donnerstag, 26. Dezem=
ber 2019 14:57 CET, <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:=
[email protected]" moz-do-not-send=3D"true">[email protected]=
inux.net</a> schrieb:=20
</pre>
          <blockquote type=3D"cite">
            <pre class=3D"moz-quote-pre" wrap=3D"">Does Pound support HST=
S ?

Does Pound support adding headers to the outgong web response?
I see the "AddHeader" option which apparently adds headers to the
incoming request (to the back-end server), but I don't see any options
that let me add headers to the outgoing response (back to the client).
</pre>
          </blockquote>
          <pre class=3D"moz-quote-pre" wrap=3D"">I've attached the HSTS p=
atch I posted years ago (updated to pound 2.8). With the patch you can ad=
d the following directive to your config at service level:
StrictTransportSecurity &lt;SECONDS&gt;

Best regards,
Frank
</pre>
          <br>
          <fieldset class=3D"mimeAttachmentHeader"></fieldset>
        </blockquote>
        <br>
        <br>
        <fieldset class=3D"mimeAttachmentHeader"></fieldset>
      </blockquote>
    </blockquote>
    <br>
  </body>
</html>

--------------B55C5DF93D935234FD30FB47--


--===============1275875274848452122==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
pound mailing list
[email protected]
https://admin.hostpoint.ch/mailman/listinfo/pound_apsis.ch

--===============1275875274848452122==--