103 lines
5.3 KiB
Markdown
103 lines
5.3 KiB
Markdown
# HTTPS Redirect + Header Hardening Report
|
|
|
|
Generated from existing AutoRecon artifacts under `results/*/scans` on 2026-04-07.
|
|
|
|
## 1) HTTP -> HTTPS redirect on every vhost
|
|
|
|
Recommended reverse-proxy baseline (Nginx):
|
|
|
|
```nginx
|
|
server {
|
|
listen 80;
|
|
listen [::]:80;
|
|
server_name _;
|
|
return 308 https://$host$request_uri;
|
|
}
|
|
```
|
|
|
|
Use `301` if legacy clients are incompatible with `308`, but do not serve app content on `:80`.
|
|
|
|
## 2) HSTS on all HTTPS responses
|
|
|
|
```nginx
|
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
|
# add ; preload only after every subdomain is permanently HTTPS
|
|
```
|
|
|
|
## 3) Baseline security headers
|
|
|
|
```nginx
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
add_header Content-Security-Policy "default-src 'self'; base-uri 'self'; frame-ancestors 'none'; object-src 'none'" always;
|
|
```
|
|
|
|
## 4) Verification matrix (`curl` + `nmap` artifacts)
|
|
|
|
| Host | HTTP :80 status | HTTPS :443 status | 80->443 redirect (301/308) | HSTS | X-CTO | Referrer-Policy | CSP |
|
|
|---|---|---|---|---|---|---|---|
|
|
| auth.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | yes | yes |
|
|
| edge.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 404` | PASS | no | yes | no | no |
|
|
| familytree.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no |
|
|
| gitea.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no |
|
|
| gotify.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no |
|
|
| grafana.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | no |
|
|
| influxdb.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no |
|
|
| kuma.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | no |
|
|
| monitor-kuma.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | no |
|
|
| nextcloud.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | yes |
|
|
| node-red.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no |
|
|
| passbolt.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | no | yes |
|
|
| portainer.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | yes |
|
|
| prometheus.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no |
|
|
| searxng.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | yes | no |
|
|
| shifts.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | yes | yes |
|
|
| stockfill.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 200` | PASS | yes | yes | no | no |
|
|
| traefik.lan.ddnsgeek.com | `HTTP/1.1 301 Moved Permanently` | `HTTP/2 302` | PASS | yes | yes | yes | no |
|
|
|
|
Verification evidence is sourced from each host's `tcp_80_http_curl.html`, `tcp_443_https_curl.html`, and `tcp_443_https_nmap.txt` scan outputs.
|
|
|
|
## 5) Per-app exceptions / tuning notes
|
|
|
|
- **edge.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- Missing HSTS on HTTPS response.
|
|
- **familytree.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- **gitea.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- **gotify.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- **grafana.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- **influxdb.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- **kuma.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- **monitor-kuma.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- **node-red.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- **passbolt.lan.ddnsgeek.com**
|
|
- Missing Referrer-Policy.
|
|
- **portainer.lan.ddnsgeek.com**
|
|
- Missing Referrer-Policy.
|
|
- **prometheus.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- **searxng.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- **stockfill.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
- Missing Referrer-Policy.
|
|
- **traefik.lan.ddnsgeek.com**
|
|
- No CSP currently set; baseline policy may break inline scripts/styles without tuning.
|
|
|
|
Suggested CSP rollout approach: deploy CSP first in `Content-Security-Policy-Report-Only`, collect violations per app, then enforce tuned policies.
|