/
757.txt
42 lines (30 loc) · 1.73 KB
/
757.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
[6] [CITE@en[RFC 6797 - HTTP Strict Transport Security (HSTS)]]
( ([TIME[2014-06-02 05:16:10 +09:00]] 版))
<http://tools.ietf.org/html/rfc6797#section-12.3>
[1] [CITE@en-US[HTTP Strict Transport Security - Web security | MDN]]
([TIME[2015-02-20 08:29:03 +09:00]] 版)
<https://developer.mozilla.org/en-US/docs/Web/Security/HTTP_strict_transport_security>
[FIG(quote)[
[FIGCAPTION[
[2] [CITE@en-US[HTTP Strict Transport Security - Web security | MDN]]
([TIME[2015-02-20 08:29:03 +09:00]] 版)
<https://developer.mozilla.org/en-US/docs/Web/Security/HTTP_strict_transport_security>
]FIGCAPTION]
> preload Optional
> See Preloading Strict Transport Security for details. Not part of the specification.
]FIG]
[FIG(quote)[
[FIGCAPTION[
[3] [CITE[HSTS Preload Submission]]
([TIME[2015-03-11 18:29:44 +09:00]] 版)
<https://hstspreload.appspot.com/>
]FIGCAPTION]
> Note that the preload flag in the HSTS header is required to confirm and authenticate your submission to the preload list. An example valid HSTS header:
> Strict-Transport-Security: max-age=10886400; includeSubDomains; preload
]FIG]
[4] [CITE[http/transport_security_state_static.json - chromium/src/net - Git at Google]]
([TIME[2015-04-17 16:56:41 +09:00]] 版)
<https://chromium.googlesource.com/chromium/src/net/+/master/http/transport_security_state_static.json>
[5] 意味もわからず [[HSTS Preload]] に登録して、サブドメインに接続できなくなったなどと困っている人もいるようです。
[CODE[includeSubDomains]] と [CODE[preload]] をヘッダーに明示的に指定しないとそうはならないはずですから、
どこかの解説サイトから理解せずにコピペして登録したのですかね。。。