Serve `*.php.net` sites with HSTS and preload them
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 48/100
Rechercherichtung
Beginnen Sie mit der Prüfung der in #623 vorgeschlagenen HTTPS-Änderungen und der verknüpften PR-Diskussion. Prüfen Sie anschließend, wie die aufgeführten *.php.net-Sites konfiguriert sind. Verifizieren Sie das Zertifikat und die HTTPS-Abdeckung für jede Site und bestätigen Sie, dass die endgültige Konfiguration HSTS ausliefert und das Browser-Preloading für den vorgesehenen Domainbereich unterstützt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
As part of #623, I took a look at the changes proposed by @localheinz. All sites I checked so far seem to be working correctly with HTTPS, and the certificates seem to be either automated with Letsencrypt, or as it the case for the main *.php.net certificate, is issued yearly by Global Sign.
Copying my comment in the linked PR above:
As far as I can see, php.net sites such as
{pecl|pear|windows|gtk|conf|qa|bugs|news|wiki}.php.netuse the same HTTPS certificate with CN*.php.net, so I assume they are safe to use with HTTPS without a doubt because any issues with this certificate will alert pretty much everyone.Looking at
{windows|downloads}.php.netcertificates on crt.sh, they seem to be automated, so they are safe to use too.
{bk2|monitoring|prototype-meta}.php.netseem to be automated too, but I have never had any insight into who and how these sites run. Again, the crt.sh data shows the certificates are being renewed correctly.
I'd like to see if we can come to a consensus on if we can serve all *.php.net sites with an HSTS header, so browsers remember and trust (TOFU) the PHP sites to always use HTTPS, even if a user clicks a plain HTTP link, loads a resource on any php.net site, etc. Further, we can preload *.php.net as HSTS to browsers. GitHub, for example, serves all of its *.github.com sites with HSTS, and preloads them as well.
- Vorherrschende Sprache
- PHP
- Sterne
- 1.1k
- Forks
- 641
- Ø Merge
- 22 Std. 36 Min.
- Gemergte PRs (30 T.)
- 16
Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus php/web-php
-
Bug Status: Needs Triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
-
Page: downloads
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 55/100
-
Page: downloads
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 62/100
-
Bug Status: Needs Triage
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 55/100
-
Bug Status: Needs Triage
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 45/100
Ähnliche Issues
-
sync-en
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 85/100
-
sync-en
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 85/100
-
Перевод устарел
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 78/100
-
[6.x]: "Cannot use object of type stdClass as array" loading Users index (regression of #19182) Offen
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100