diff --git a/https-header-hardening-report.md b/https-header-hardening-report.md new file mode 100644 index 0000000..24b7af3 --- /dev/null +++ b/https-header-hardening-report.md @@ -0,0 +1,102 @@ +# HTTPS Redirect + Header Hardening Report + +Generated from existing AutoRecon artifacts under `results/*/scans` on 2026-04-07. + +## 1) HTTP -> HTTPS redirect on every vhost + +Recommended reverse-proxy baseline (Nginx): + +```nginx +server { + listen 80; + listen [::]:80; + server_name _; + return 308 https://$host$request_uri; +} +``` + +Use `301` if legacy clients are incompatible with `308`, but do not serve app content on `:80`. + +## 2) HSTS on all HTTPS responses + +```nginx +add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; +# add ; preload only after every subdomain is permanently HTTPS +``` + +## 3) Baseline security headers + +```nginx +add_header X-Content-Type-Options "nosniff" always; +add_header Referrer-Policy "strict-origin-when-cross-origin" always; +add_header Content-Security-Policy "default-src 'self'; base-uri 'self'; frame-ancestors 'none'; object-src 'none'" always; +``` + +## 4) Verification matrix (`curl` + `nmap` artifacts) + +| Host | HTTP :80 status | HTTPS :443 status | 80->443 redirect (301/308) | HSTS | X-CTO | Referrer-Policy | CSP | +|---|---|---|---|---|---|---|---| +| auth.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | yes | yes | +| edge.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 404` | PASS | no | yes | no | no | +| familytree.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no | +| gitea.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no | +| gotify.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no | +| grafana.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | no | +| influxdb.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no | +| kuma.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | no | +| monitor-kuma.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | no | +| nextcloud.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | yes | +| node-red.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no | +| passbolt.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | yes | +| portainer.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | yes | +| prometheus.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no | +| searxng.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | yes | no | +| shifts.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | yes | yes | +| stockfill.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no | +| traefik.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no | + +Verification evidence is sourced from each host's `tcp_80_http_curl.html`, `tcp_443_https_curl.html`, and `tcp_443_https_nmap.txt` scan outputs. + +## 5) Per-app exceptions / tuning notes + +- **edge.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. + - Missing HSTS on HTTPS response. +- **familytree.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. +- **gitea.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. +- **gotify.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. +- **grafana.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. +- **influxdb.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. +- **kuma.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. +- **monitor-kuma.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. +- **node-red.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. +- **passbolt.lan.ddnsgeek.com** + - Missing Referrer-Policy. +- **portainer.lan.ddnsgeek.com** + - Missing Referrer-Policy. +- **prometheus.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. +- **searxng.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. +- **stockfill.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + - Missing Referrer-Policy. +- **traefik.lan.ddnsgeek.com** + - No CSP currently set; baseline policy may break inline scripts/styles without tuning. + +Suggested CSP rollout approach: deploy CSP first in `Content-Security-Policy-Report-Only`, collect violations per app, then enforce tuned policies. diff --git a/verification/curl-summary.txt b/verification/curl-summary.txt new file mode 100644 index 0000000..4516a76 --- /dev/null +++ b/verification/curl-summary.txt @@ -0,0 +1,306 @@ +### auth.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:53 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:53 GMT +server: envoy +connection: close + + +### edge.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:54 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:54 GMT +server: envoy +connection: close + + +### familytree.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:54 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:54 GMT +server: envoy +connection: close + + +### gitea.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:54 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:54 GMT +server: envoy +connection: close + + +### gotify.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:55 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:55 GMT +server: envoy +connection: close + + +### grafana.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:55 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:55 GMT +server: envoy +connection: close + + +### influxdb.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:55 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:55 GMT +server: envoy +connection: close + + +### kuma.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:55 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy +connection: close + + +### monitor-kuma.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy +connection: close + + +### nextcloud.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy +connection: close + + +### node-red.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy +connection: close + + +### passbolt.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:56 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy +connection: close + + +### portainer.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy +connection: close + + +### prometheus.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy +connection: close + + +### searxng.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy +connection: close + + +### shifts.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:57 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:58 GMT +server: envoy +connection: close + + +### stockfill.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:58 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:58 GMT +server: envoy +connection: close + + +### traefik.lan.ddnsgeek.com +-- :80 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:58 GMT +server: envoy + +-- :443 -- +HTTP/1.1 403 Forbidden +content-length: 16 +content-type: text/plain +date: Tue, 07 Apr 2026 03:49:58 GMT +server: envoy +connection: close + +