{"id":86873,"date":"2024-01-29T21:39:11","date_gmt":"2024-01-29T13:39:11","guid":{"rendered":"http:\/\/lrxjmw.cn\/?p=86873"},"modified":"2024-01-29T21:39:11","modified_gmt":"2024-01-29T13:39:11","slug":"chrome-abandon-hpkp","status":"publish","type":"post","link":"https:\/\/lrxjmw.cn\/chrome-abandon-hpkp.html","title":{"rendered":"Chrome \u6216\u5c06\u4e8e2018\u5e74\u6b63\u5f0f\u5f03\u7528 HPKP \u516c\u94a5\u56fa\u5b9a\u6807\u51c6"},"content":{"rendered":"
\u5bfc\u8bfb<\/td>\n | \u65e9\u4e9b\u5e74\u8c37\u6b4c\u5de5\u7a0b\u5e08\u4e3a\u4e86\u63d0\u9ad8\u4e92\u8054\u7f51\u6574\u4f53\u7684\u5b89\u5168\u6027\u907f\u514d\u56e0\u8bc1\u4e66\u9881\u53d1\u673a\u6784\u8fdd\u89c4\u64cd\u4f5c\u800c\u8bbe\u8ba1\u4e86 HPKP \u516c\u94a5\u56fa\u5b9a\u6807\u51c6\u3002\u516c\u94a5\u56fa\u5b9a\u5141\u8bb8\u7f51\u7ad9\u5728\u670d\u52a1\u5668\u90e8\u7f72\u8bc1\u4e66\u9881\u53d1\u673a\u6784\u7684\u54c8\u5e0c\u503c\uff0c \u82e5\u7f51\u7ad9\u4f7f\u7528\u7684\u8bc1\u4e66\u4e0e\u56fa\u5b9a\u7684\u54c8\u5e0c\u4e0d\u5bf9\u5e94\u5219\u62d2\u7edd\u8fde\u63a5\u3002\u516c\u94a5\u56fa\u5b9a\u7684\u73b0\u5b9e\u610f\u4e49\u5728\u4e8e\u5982\u679c\u6709 CA \u8bc1\u4e66\u9881\u53d1\u673a\u6784\u8fdd\u89c4\u5411\u67d0\u4e2a\u57df\u540d\u79c1\u81ea\u7b7e\u53d1\u8bc1\u4e66\u90a3\u4e48\u4e5f\u65e0\u6cd5\u5b9e\u73b0\u5bf9\u7f51\u7ad9\u7684\u52ab\u6301\u3002\u4f46\u662f\u73b0\u5728\u8c37\u6b4c\u6d4f\u89c8\u5668\u5df2\u7ecf\u51b3\u5b9a\u5f03\u7528 HPKP \u516c\u94a5\u56fa\u5b9a\u6807\u51c6\uff0c\u9884\u8ba1\u5c06\u4f1a\u5728 2018 \u5e74 5 \u6708\u4efd\u5230\u6765\u7684\u6b63\u5f0f\u7248\u91cc\u6b63\u5f0f\u5f03\u7528\u3002<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n <\/p>\n \u90a3\u4e48\u95ee\u9898\u5230\u5e95\u53d1\u751f\u5728\u54ea\u91cc\uff1f<\/strong><\/div>\n HPKP \u516c\u94a5\u56fa\u5b9a\u6240\u643a\u5e26\u7684\u662f\u4e2d\u7ea7\u8bc1\u4e66\u6216\u8005\u6839\u8bc1\u4e66\u7684\u54c8\u5e0c\u503c\uff0c\u5e76\u4e0e\u7ec8\u7aef\u6d4f\u89c8\u5668\u7ea6\u5b9a\u6b64\u54c8\u5e0c\u901a\u5e38\u4f1a\u5728 1 \u5e74\u5de6\u53f3\u5931\u6548\u3002<\/p>\n \u4f8b\u5982\u84dd\u70b9\u7f51\u76ee\u524d\u4f7f\u7528\u7684\u662f TrustAsia\uff08\u4e2d\u7ea7 CA\uff09\u63d0\u4f9b\u7684\u8bc1\u4e66\uff0c\u6211\u4eec\u5df2\u7ecf\u5c06 TrustAsia \u7684\u4e2d\u7ea7\u8bc1\u4e66\u54c8\u5e0c\u8fdb\u884c\u56fa\u5b9a\u3002<\/p>\n server\r\n {\r\n listen 443 ssl http2;\r\n ssl on;\r\n ssl_certificate \/usr\/local\/nginx\/conf\/vhost\/crt\/www.landiannews.com.crt;\r\n ssl_certificate_key \/usr\/local\/nginx\/conf\/vhost\/crt\/www.landiannews.com.key;\r\n # \u542f\u7528\u4e25\u683c\u5b89\u5168\u4f20\u8f93HSTS \r\n\tadd_header Strict-Transport-Security \"max-age=63072000; includeSubdomains; preload\";\r\n\t# \u542f\u7528 HPKP \u516c\u94a5\u56fa\u5b9a\r\n add_header Public-Key-Pins 'pin-sha256=\"IiSbZ4pMDEyXvtl7Lg8K3FNmJcTAhKUTrB2FQOaAO\/s=\"; pin-sha256=\"klO23nT2ehFDXCfx3eHTDRESMz3asj1muO+4aIdjiuY=\"; max-age=2592000; includeSubDomains';\r\n ssl_session_timeout 5m;\r\n }\r\n<\/pre>\n |