New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 792044 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 3
Type: Feature



Sign in to add a comment

make HSTS entries configurable for intranet usage

Reported by christ...@tramnitz.com, Dec 5 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36

Steps to reproduce the problem:
Trying to enforce HTTPS in intranet environments via HSTS may fail with current approach. Organizations won't be willing to add their intranet domains in a public list. The overhead of having users manage intranet sites via chrome://net-internals/#hsts is too large.

What is the expected behavior?
Having a configurable list of *additional* HSTS entries. This should either be configurable/packageable via customized install/central policies or an configurable to be downloadable from an authoritative URL.

What went wrong?
Currently HSTS are hard-coded to what's public or users can enter additional domains manually.

Did this work before? No 

Chrome version: 62.0.3202.94  Channel: stable
OS Version: OS X 10.13.1
Flash Version: 

This is loosely related to issue 451295. However, since we are talking about intranet pages here, there is a potential to have everything under control and no assumptions how the site owner behaves have to be made.

Having such a feature would allow organizations migrate to https-only in their intranet more quickly:
- on an site-by-site base enable https
- add the site to the custom HSTS preload list
- regardless how the site is access (typed without scheme, from bookmark from an old link), the request is made to https directly
- site access via http can be safely disabled
 
ill leave now sorry for the trouble, bye. 
Cc: pastarmovj@chromium.org yini...@chromium.org

Comment 3 by pmarko@chromium.org, Dec 11 2017

Owner: dskaram@chromium.org
David, who could triage this?

IIUC it's about a policy for adding entries to the list of domains chrome should only access through HTTPS (https://www.chromium.org/hsts).

Comment 4 by pmarko@chromium.org, Dec 11 2017

Owner: blumberg@chromium.org
Assigning to Matt for triage.
Labels: -Pri-2 Pri-3
Thank you, we will consider this feature request for a future release.

By the way, is this a mac-only request?
Thanks for considering this one.
This is not Mac-only but should be possible on all OS’es.
Owner: georgesak@chromium.org
Cc: goanuj@chromium.org
Labels: -Type-Bug Type-Feature
Owner: kcnair@google.com
Kiran, looks like a FR for your team
Status: Assigned (was: Unconfirmed)

Sign in to add a comment