Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[feature request] HCM option to enforce that host header is allowed by the cert served #17258

Closed
lambdai opened this issue Jul 7, 2021 · 2 comments
Labels
stale stalebot believes this issue/PR has not been touched recently

Comments

@lambdai
Copy link
Contributor

lambdai commented Jul 7, 2021

Http host (or :authority in h2) header should match dns name in Subject Alternative Name.

To be clear, the dns name is not SNI that are referred by FilterChainMatch and filled by tls_inspector listener filter.

@lambdai lambdai mentioned this issue Jul 7, 2021
@github-actions
Copy link

github-actions bot commented Aug 6, 2021

This issue has been automatically marked as stale because it has not had activity in the last 30 days. It will be closed in the next 7 days unless it is tagged "help wanted" or "no stalebot" or other activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale stalebot believes this issue/PR has not been touched recently label Aug 6, 2021
@github-actions
Copy link

This issue has been automatically closed because it has not had activity in the last 37 days. If this issue is still valid, please ping a maintainer and ask them to label it as "help wanted" or "no stalebot". Thank you for your contributions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
stale stalebot believes this issue/PR has not been touched recently
Projects
None yet
Development

No branches or pull requests

1 participant