2020-11-03 06:17:01 +08:00
|
|
|
# HSTS support
|
|
|
|
|
2021-05-28 18:34:07 +08:00
|
|
|
HTTP Strict-Transport-Security. Added as experimental in curl
|
|
|
|
7.74.0. Supported "for real" since 7.77.0.
|
2020-11-03 06:17:01 +08:00
|
|
|
|
|
|
|
## Standard
|
|
|
|
|
2022-01-22 02:52:33 +08:00
|
|
|
[HTTP Strict Transport Security](https://datatracker.ietf.org/doc/html/rfc6797)
|
2020-11-03 06:17:01 +08:00
|
|
|
|
|
|
|
## Behavior
|
|
|
|
|
|
|
|
libcurl features an in-memory cache for HSTS hosts, so that subsequent
|
2024-01-23 22:12:09 +08:00
|
|
|
HTTP-only requests to a hostname present in the cache will get internally
|
2020-11-03 06:17:01 +08:00
|
|
|
"redirected" to the HTTPS version.
|
|
|
|
|
|
|
|
## `curl_easy_setopt()` options:
|
|
|
|
|
|
|
|
- `CURLOPT_HSTS_CTRL` - enable HSTS for this easy handle
|
2024-01-23 22:12:09 +08:00
|
|
|
- `CURLOPT_HSTS` - specify filename where to store the HSTS cache on close
|
2020-11-03 06:17:01 +08:00
|
|
|
(and possibly read from at startup)
|
|
|
|
|
2022-09-21 05:30:19 +08:00
|
|
|
## curl command line options
|
2020-11-03 06:17:01 +08:00
|
|
|
|
|
|
|
- `--hsts [filename]` - enable HSTS, use the file as HSTS cache. If filename
|
|
|
|
is `""` (no length) then no file will be used, only in-memory cache.
|
|
|
|
|
|
|
|
## HSTS cache file format
|
|
|
|
|
|
|
|
Lines starting with `#` are ignored.
|
|
|
|
|
|
|
|
For each hsts entry:
|
|
|
|
|
|
|
|
[host name] "YYYYMMDD HH:MM:SS"
|
|
|
|
|
2022-09-21 05:30:19 +08:00
|
|
|
The `[host name]` is dot-prefixed if it includes subdomains.
|
2020-11-03 06:17:01 +08:00
|
|
|
|
|
|
|
The time stamp is when the entry expires.
|
|
|
|
|
|
|
|
## Possible future additions
|
|
|
|
|
2022-09-21 05:30:19 +08:00
|
|
|
- `CURLOPT_HSTS_PRELOAD` - provide a set of HSTS host names to load first
|
2020-11-03 06:17:01 +08:00
|
|
|
- ability to save to something else than a file
|