-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
The HSTS config for trunk.rdoproject.org overrides *.rdoproject.org #40
Comments
Where is that configured in httpd config? [1] https://www.owasp.org/index.php/HTTP_Strict_Transport_Security_Cheat_Sheet |
From bash history I see @javierpena used puppet apache module to configure httpd, so leaving this one for him. |
I think the HSTS header is defined in rdoproject.org rather than trunk.rdoproject.org. Using a Firefox extension, I've seen that anytime we fetch the CSS content from rdoproject.org, we get the Strict-Transport-Security header. Since the CSS is loaded by the front page, we get the HSTS content. Just tried the reproduction steps using http://trunk.rdoproject.org/centos7/report.html instead of the front page, and no HSTS is enforced. |
yeah, that's set on rdoproject.org. |
That's interesting because visiting rdoproject.org doesn't generate the problem for me, just trunk. |
How to reproduce:
Now.. we could argue that everything under rdoproject.org should be SSL, but it's probably not a decision that should be made by trunk.rdoproject.org :)
The text was updated successfully, but these errors were encountered: