Uploaded image for project: 'Traffic Server'
  1. Traffic Server
  2. TS-4502

HSTS should clip to the certificate expiry

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • sometime
    • SSL
    • None

    Description

      When using proxy.config.ssl.hsts_max_age to send a strict transport security header, we should examine the expiry of the certificate we are servige the request with, and clip the max HSTS age to the expiry of the certificate. This would prevent browsers puking on HSTS when certificates expire legitimately.

      Attachments

        Activity

          People

            Unassigned Unassigned
            jamespeach James Peach
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated: