Error with HTTP Strict Transport Security (HSTS)
-
Hello guys,
i have configured pfsense / squid with certificates and it works fine.Since yesterday and in particular "only one site" I have this error on the certificate
"www.sito.com uses a security policy called HTTP Strict Transport Security (HSTS). This means that Firefox can only connect securely and it is not possible to add an exception to visit this site."
and more specifically
The pfsense certificate has been distributed online and has been running for about 1 year.
Has anyone encountered the same problem?
Greetings
Michele
-
@michele-trotta said in Error with HTTP Strict Transport Security (HSTS):
Has anyone encountered the same problem?
Noop.
You've hidden the site's name, so how can I/we test ?If the site's administrator used a certificate authority that has fallen into disgrace, then browsers quickly will remove their root certs from their internal "trusted list". All certificates signed (created) with this root certificate will become not rusted.
And worse : getting a new certificate from another certificate authority and putting that in place wouldn't help much, as the, now retired, certificate info, according to HSTS rules, will get stored deep down in the browser's HSTS cache.
I guess the site's admin has to go through the certificate revocation procedure.And we all take note : before asking for that HSTS flag to be set on a certificate, better be sure
all the down side aspects are understoodIt's nice to have all green marks everywhere 'this is an example of one of my own 'dummy/fool-around' sites, but when things go down hill, the slope gets steep.
Btw : maybe I should lower this a bit :
-
@gertjan said in Error with HTTP Strict Transport Security (HSTS):
It's nice to have all green marks everywhere 'this is an example of one of my own 'dummy/fool-around' sites, but when things go down hill, the slope gets steep.
Btw : maybe I should lower this a bit :Hi gertjan,
thanks for the quick response!!!
the external site is www.arcafondi.itGreetings
Michele
-
Hi gertjan,
now the site is reachable with pfsense without errors and most likely the administrator has changed the certificates correctly.
Thanks for the explanation!
Michele
-
Hi guys
since this morning I have the exact same problem with another site https://www.regione.lombardia.it
To temporarily solve the problem, I added the site to the ACLs withelist of the Squid proxy Server.
I wanted to understand what actions to take and if I can improve my setup.
@Gertjan can I lower the parameter you highlighted after that?Thanks again and good job
Michele