-1

Is there any way to use a Strict-Transport security header on a site but still have non-ssl sub-domains?

4

1 回答 1

0

你可以只设置Strict-Transport-Security没有includeSubDomains. 例如,如果您设置Strict-Transport-Security: max-age=31536000https://example.com,则浏览器不会对nonsslsub.example.com.

于 2017-06-11T02:02:50.113 回答