mirror of
https://github.com/curl/curl.git
synced 2026-04-11 12:01:42 +08:00
Up from 1K.
Reduces the risk that someone could flush the list by tricking a user to
do many transfers to new hostnames.
Document the limit.
Follow-up to 03a792b186
Closes #21200
1.3 KiB
1.3 KiB
HSTS support
HTTP Strict-Transport-Security. Added as experimental in curl 7.74.0. Supported "for real" since 7.77.0.
Standard
HTTP Strict Transport Security
Behavior
libcurl features an in-memory cache for HSTS hosts, so that subsequent HTTP-only requests to a hostname present in the cache gets internally "redirected" to the HTTPS version.
Since curl 8.20.0, libcurl keeps no more than the most recently added 10,000 unique HSTS hostnames.
curl_easy_setopt() options:
CURLOPT_HSTS_CTRL- enable HSTS for this easy handleCURLOPT_HSTS- specify filename where to store the HSTS cache on close (and possibly read from at startup)
curl command line options
--hsts [filename]- enable HSTS, use the file as HSTS cache. If filename is""(no length) then no file is used, only in-memory cache.
HSTS cache file format
Lines starting with # are ignored.
For each hsts entry:
[hostname] "YYYYMMDD HH:MM:SS"
The [hostname] is dot-prefixed if it includes subdomains.
The time stamp is when the entry expires.
Possible future additions
CURLOPT_HSTS_PRELOAD- provide a set of HSTS hostnames to load first- ability to save to something else than a file