标签: ssl https strict-transport-security
有没有办法在网站上使用Strict-Transport安全标头,但仍然有非ssl子域?
答案 0 :(得分:0)
您只需设置Strict-Transport-Security标题而不includeSubDomains。例如,如果您在Strict-Transport-Security: max-age=31536000上设置https://example.com,那么浏览器就不会为nonsslsub.example.com强制实施HTTPS。
Strict-Transport-Security
includeSubDomains
Strict-Transport-Security: max-age=31536000
https://example.com
nonsslsub.example.com