[tor-bugs] #21705 [Internal Services/Tor Sysadmin Team]: Invalid Strict-Transport-Security header

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Mar 11 08:42:28 UTC 2017


#21705: Invalid Strict-Transport-Security header
-------------------------------------------------+---------------------
 Reporter:  cypherpunks                          |          Owner:  tpa
     Type:  defect                               |         Status:  new
 Priority:  Medium                               |      Milestone:
Component:  Internal Services/Tor Sysadmin Team  |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:                                       |  Actual Points:
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+---------------------
Changes (by karsten):

 * owner:  metrics-team => tpa
 * component:  Metrics/Onionoo => Internal Services/Tor Sysadmin Team


Comment:

 Indeed, thanks for the report!

 Looks like this invalid header comes back from orestis, whereas omeiense
 returns the correct header:

 {{{
 < * Connected to onionoo.torproject.org (78.47.38.227) port 443 (#0)
 ---
 > * Connected to onionoo.torproject.org (89.45.235.19) port 443 (#0)
 22,23c22,25
 < < X-Varnish: 122699485 122515587
 < < Age: 82
 ---
 > < X-Varnish: 122576486 122515587
 > < Via: 1.1 varnish-v4
 > < X-Varnish: 141652475
 > < Age: 104
 27c29
 < < Strict-Transport-Security: max-age=15768000
 ---
 > < Strict-Transport-Security: "max-age=15768000"
 }}}

 Reassigning to our friendly sysadmin team.  (Thanks!)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21705#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list