Serve `*.php.net` sites with HSTS and preload them
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
Direzione di ricerca
Inizia esaminando le modifiche HTTPS proposte in #623 e la discussione della PR collegata, quindi verifica come sono configurati i siti *.php.net elencati. Verifica il certificato e la copertura HTTPS per ogni sito e conferma che la configurazione finale fornisca HSTS e supporti il preloading del browser per l'ambito di dominio previsto.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
As part of #623, I took a look at the changes proposed by @localheinz. All sites I checked so far seem to be working correctly with HTTPS, and the certificates seem to be either automated with Letsencrypt, or as it the case for the main *.php.net certificate, is issued yearly by Global Sign.
Copying my comment in the linked PR above:
As far as I can see, php.net sites such as
{pecl|pear|windows|gtk|conf|qa|bugs|news|wiki}.php.netuse the same HTTPS certificate with CN*.php.net, so I assume they are safe to use with HTTPS without a doubt because any issues with this certificate will alert pretty much everyone.Looking at
{windows|downloads}.php.netcertificates on crt.sh, they seem to be automated, so they are safe to use too.
{bk2|monitoring|prototype-meta}.php.netseem to be automated too, but I have never had any insight into who and how these sites run. Again, the crt.sh data shows the certificates are being renewed correctly.
I'd like to see if we can come to a consensus on if we can serve all *.php.net sites with an HSTS header, so browsers remember and trust (TOFU) the PHP sites to always use HTTPS, even if a user clicks a plain HTTP link, loads a resource on any php.net site, etc. Further, we can preload *.php.net as HSTS to browsers. GitHub, for example, serves all of its *.github.com sites with HSTS, and preloads them as well.
- Lingua principale
- PHP
- Stelle
- 1.1k
- Fork
- 641
- Merge medio
- 22h 36m
- PR unite (30g)
- 16
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di php/web-php
-
Bug Status: Needs Triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
Page: downloads
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
-
Page: downloads
Difficoltà 3/5 1-2 giorni Idoneità per principianti 62/100
-
Bug Status: Needs Triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
-
Bug Status: Needs Triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
Issue simili
-
sync-en
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
-
sync-en
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
-
Перевод устарел
Difficoltà 1/5 1-3 ore Idoneità per principianti 78/100
-
[6.x]: "Cannot use object of type stdClass as array" loading Users index (regression of #19182) Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100