Skip to content
This repository was archived by the owner on Nov 6, 2023. It is now read-only.

Conversation

@ghost
Copy link

@ghost ghost commented Mar 6, 2016

No description provided.

@fuglede
Copy link
Contributor

fuglede commented Mar 6, 2016

Thanks for the PR! A few issues in this one:

  • The test URL is actually redundant; the target hosts will automatically be tested in a ruleset like this.

  • The non-www host does not actually resolve, so it should not be covered in the ruleset (shameless plug: Add Travis test for ruleset test URLs #3107 would have caught this);

    $ curl https://mbnet.pt
    curl: (6) Could not resolve host: mbnet.pt

While not related to the ruleset, it's kind of a curious collection of headers that they have decided to serve:

$ curl -I https://www.mbnet.pt
...
Strict-Transport-Security: max-age=15552000; includeSubDomains
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload

@ghost
Copy link
Author

ghost commented Mar 6, 2016

The duplicate HSTS headers are against the specs, I will report it to them.

@fuglede
Copy link
Contributor

fuglede commented Mar 6, 2016

Yeah, there's the duplication, but also the preload token is not all that useful when the root domain does not resolve.

fuglede added a commit that referenced this pull request Mar 6, 2016
@fuglede fuglede merged commit 9e67fc8 into EFForg:master Mar 6, 2016
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants