1 year ago
#383393
samtech
HTTPS and HSTS headers issue AWS
In my scenario we currently have www3.qwerty.com routing through a few different paths. Could you please advise how we should correct this to be a better approach, possibly just redirecting even?
"The HTTP site redirects users to a new URL in a way that cannot be secured with HTTPS and HSTS headers. This leaves users open to man-in-the-middle attackers who can redirect them to a fraudulent/ spoofed version of the intended site.
“Site Does Not Enforce HTTPS” issue type for more information regarding man-in-the-middle scenarios."
From "
http://www3.qwerty.com/, 301, https://www.qwerty.com/
"
we don't need that domain though so it'd best to just have it go directly to www.qwerty.com rather than the reroutes either cname or load balancer came to mind.
What is the best way to accomplish this?
amazon-web-services
https
dns
http-headers
amazon-route53
0 Answers
Your Answer