Uploaded image for project: 'Dev - Nexus Repo'
  1. Dev - Nexus Repo
  2. NEXUS-20269

remove jetty-http-redirect-to-https.xml file from distribution

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 3.17.0, 3.19.1
    • Fix Version/s: 3.20.0
    • Component/s: Transport
    • Labels:
    • Release Note:
      Yes

      Description

      It is not a good security practice to HTTP redirect plain http requests to https.

      We ship our distribution with jetty-http-redirect-to-https.xml file which helps one configure this redirection.

      This is why HSTS was invented ( https://tools.ietf.org/html/rfc6797#section-6.1.1 ) - to help avoid this bad practice. See NEXUS-20268.

      Expected

      • remove jetty-http-redirect-to-https.xml from the distribution and put the instructions and appropriate WARNings about using it in a KB article
      • mention in release notes so customers are forewarned on upgrade to a version that does not include it

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned
              Reporter:
              plynch Peter Lynch
              Last Updated By:
              Peter Lynch
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Date of First Response:

                  tigCommentSecurity.panel-title