HSTS
HSTS
(= HTTP Strict Transport Security,
"HTTP range transporditurve")
olemus
turvapoliitika kehtestuse mehhanism, mis sunnib
protokolli HTTP asemel protokolli HTTPS kasutades
looma turvalist veebiühendust ja tõrjub näiteks
madaldusründeid ja seansikaaperdust
=
a web server directive that informs user agents and web browsers how to handle its connection through a response header sent at the very beginning and back to the browser
kehtestus
veebiserver määrab
selle mehhanismi kasutamise
kasutajaagendile saadetava
vastussõnumi HSTS-päiseväljal
ülevaateid
https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
https://www.mgm-sp.com/wp-content/uploads/HTTP_Strict_Transport_Security_HSTS_Whitepaper.pdf
https://www.owasp.org/index.php/HTTP_Strict_Transport_Security_Cheat_Sheet
standard
https://tools.ietf.org/html/rfc6797
turvalisus
https://www.blackhat.com/docs/eu-14/materials/eu-14-Selvi-Bypassing-HTTP-Strict-Transport-Security-wp.pdf
https://www.usenix.org/system/files/conference/foci18/foci18-paper-syverson.pdf
vt ka
- HSTS-eelloend