New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 599316 link

Starred by 2 users

Issue metadata

Status: Archived
Owner: ----
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

Provide support for bulk HSTS subdomain removal

Reported by m...@wake.io, Mar 31 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.87 Safari/537.36

Example URL:
chrome://net-internals/#hsts

Steps to reproduce the problem:
1. Set HSTS header on server
2. Navigate to https://subdomain.domain.com and https://subdomain2.domain.com
3. Navigate to chrome://net-internals/#hsts in the Delete domain section type *.domain.com and click delete

What is the expected behavior?
All subdomains of domain.com have been cleared of existing HSTS headers

What went wrong?
All subdomains continue to utilize existing HSTS headers

Did this work before? N/A 

Chrome version: 49.0.2623.87  Channel: n/a
OS Version: OS X 10.10.5
Flash Version:
 
Components: -Internals>Network Internals>Network>Logging
Components: -Internals>Network>Logging Internals>Network>SSL
Components: -Internals>Network>SSL Internals>Network>Logging
Cc: lgar...@chromium.org est...@chromium.org
I don't know if this should be high enough priority that we'll get to it any time soon, but let me offer two immediate workarounds:

- If you *can* still serve valid HSTS from those subdomains, serve it with a max-age=0 and trigger a load of a resources to each relevant subdomain.

- Script the chrome://net-internals/#hsts page:
    for (domain of domainList) {
      document.getElementById("hsts-view-delete-input").value = domain;
      document.getElementById("hsts-view-delete-submit").click()
    }

Components: Internals>Network>DomainSecurityPolicy
Project Member

Comment 7 by sheriffbot@chromium.org, Feb 19 2018

Status: Archived (was: Unconfirmed)
Issue has not been modified or commented on in the last 365 days, please re-open or file a new bug if this is still an issue.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment