Files
llm-wiki/raw/official-docs/owasp-hsts-cheat-sheet.md
T

8.7 KiB

title, source_type, url, archive_url, status, confidence, related_branches, related_projects, tags, created, last_reviewed
title source_type url archive_url status confidence related_branches related_projects tags created last_reviewed
OWASP HSTS Cheat Sheet — Strict-Transport-Security header + preload risks official-doc https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Strict_Transport_Security_Cheat_Sheet.html raw high
feature-keycloak-https-termination-caddy-nginx
ca-skeleton-operational-contract
ca-security
hsts
owasp
https
tls
strict-transport-security
official-doc
2026-05-27 2026-05-27

OWASP HSTS Cheat Sheet

Layer: raw/official-docs/ — OWASP Foundation 발행 HTTP Strict Transport Security cheat sheet. ca-tmpl Keycloak HTTPS termination 결정 D5 (HSTS 헤더 설정 정책 및 preload 채택 여부) 의 운영 원칙 reference.

Parent / 활용 branch (필수)

Branch 이 자료가 정당화하는 결정
raw/branch-notes/feature-keycloak-https-termination-caddy-nginx D5 (Caddy/Nginx reverse proxy 의 HSTS 헤더 설정 정책 — max-age 값, includeSubDomains, preload 채택 여부) 의 운영 원칙 1차 근거

컨텍스트 / 왜 저장했는지

ca-tmpl Keycloak HTTPS termination 에서 "왜 max-age 가 최소 6개월 이상이어야 하는가", "왜 preload 는 permanent consequences 를 가지는가", "왜 HSTS 헤더는 HTTPS 응답에서만 전송되어야 하는가" 결정의 1차 근거. HSTS 자체는 RFC 6797 표준이지만 운영 권고는 OWASP cheatsheet 의 community 합의를 따름.

출처 / Source

핵심 인용 / Key quotes (verbatim, captured 2026-05-27)

[§Introduction] "HTTP Strict Transport Security (also named HSTS) is an opt-in security enhancement that is specified by a web application through the use of a special response header."

[§Threats] "HSTS automatically redirects HTTP requests to HTTPS for the target domain"

[§Threats] "HSTS does not allow a user to override the invalid certificate message"

[§Examples] "Strict-Transport-Security: max-age=63072000; includeSubDomains; preload"

[§Examples] "Sending the preload directive from your site can have PERMANENT CONSEQUENCES"

[§Problems] "Cookies can be manipulated from sub-domains, so omitting the includeSubDomains option permits a broad range of cookie-related attacks"

[§Browser Support] "As of September 2019 HSTS is supported by all modern browsers"

Claims Extracted / 추출된 주장

Claim ID Claim (이 자료가 직접 말하는 것) Evidence quote Strength Applies to Does not prove
OWASP-HSTS-C1 HSTS 는 opt-in security enhancement — 응답 헤더로 지정 [§Introduction] "HTTP Strict Transport Security (also named HSTS) is an opt-in security enhancement that is specified by a web application through the use of a special response header." official-reference (OWASP cheatsheet — 표준 아님, RFC 6797 별도) HSTS 활성화는 application 선택 결정 모든 application 이 HSTS 를 켜야 한다는 의무는 아님 — opt-in
OWASP-HSTS-C2 HSTS 활성 시 브라우저는 target domain 의 HTTP 요청을 자동으로 HTTPS 로 redirect [§Threats] "HSTS automatically redirects HTTP requests to HTTPS for the target domain" official-reference HTTP → HTTPS upgrade 정책 (server-side redirect + HSTS 보완 관계) server-side 301 redirect 가 불필요하다는 뜻은 아님 — 첫 방문 (TOFU) 시 redirect 필요
OWASP-HSTS-C3 HSTS 활성 시 사용자는 invalid certificate 경고를 override 할 수 없음 (proceed anyway 불가) [§Threats] "HSTS does not allow a user to override the invalid certificate message" official-reference 인증서 만료/오설정 시 사용자가 강제 접근할 수 없음을 운영팀이 인지하는 결정 자체 서명 인증서 환경 (개발) 에서도 동일하므로 dev 환경 HSTS 활성 시 운영 부담 발생
OWASP-HSTS-C4 권장 헤더 예시: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload (2년) [§Examples] "Strict-Transport-Security: max-age=63072000; includeSubDomains; preload" official-reference max-age 값 결정 (예시상 2년 = 63072000s) 모든 사이트가 정확히 2년을 써야 한다는 뜻은 아님 — preload 등록 요구사항이 별도 (HSTS preload list 는 1년 이상 요구)
OWASP-HSTS-C5 preload directive 는 PERMANENT CONSEQUENCES 를 가짐 — 사이트에서 보내면 영구 등록 위험 [§Examples] "Sending the preload directive from your site can have PERMANENT CONSEQUENCES" official-reference preload 채택 여부 신중 결정 — 제거 절차가 복잡하고 시간 오래 걸림 "preload 를 절대 쓰지 말라" 는 뜻은 아님 — 신중하게 쓰라는 경고
OWASP-HSTS-C6 includeSubDomains 옵션을 생략하면 sub-domain 에서 cookie 조작 등 cookie 관련 공격 광범위 허용 [§Problems] "Cookies can be manipulated from sub-domains, so omitting the includeSubDomains option permits a broad range of cookie-related attacks" official-reference includeSubDomains 활성 권고 결정 모든 환경에서 의무라는 뜻은 아님 — 일부 sub-domain 이 HTTPS 미지원이면 활성화 위험
OWASP-HSTS-C7 HSTS 는 2019년 9월 기준 모든 modern browser 에서 지원됨 [§Browser Support] "As of September 2019 HSTS is supported by all modern browsers" official-reference HSTS 호환성에 대한 우려 없이 배포 가능한 결정 모든 client (CLI / IoT / legacy) 가 지원한다는 뜻은 아님 — modern browser 범위만

Usage Boundaries / 적용 경계

  • 이 자료가 직접 증명하는 것 (2026-05-27 WebFetch verbatim 확인):
    • OWASP-HSTS-C1: HSTS opt-in
    • OWASP-HSTS-C2: 브라우저의 자동 HTTPS upgrade
    • OWASP-HSTS-C3: invalid cert override 불가
    • OWASP-HSTS-C4: 권장 헤더 예시 (2년 max-age + includeSubDomains + preload)
    • OWASP-HSTS-C5: preload 의 permanent consequences 경고
    • OWASP-HSTS-C6: includeSubDomains 생략 시 cookie 공격 위험
    • OWASP-HSTS-C7: 모든 modern browser 지원 (2019.09 기준)
  • 이 자료가 증명하지 않는 것:
    • HSTS 자체의 정확한 wire format / parser 동작 — RFC 6797 위임
    • preload list 등록 정책 (1년 이상 max-age, includeSubDomains 의무 등) — hstspreload.org 별도 사이트 위임
    • Caddy / Nginx 별 구체적 directive 문법 — 벤더 doc 위임
    • TOFU (Trust On First Use) attack 방어 — preload 가 해결책이지만 본 cheatsheet 는 위험만 경고
    • OWASP cheatsheet 는 권고이며 강제 표준이 아님. RFC 6797 이 normative 표준.
  • 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
    • ca-tmpl 의 Caddy/Nginx config 에서 HSTS 헤더가 HTTPS 응답에서만 전송되는지 확인 (HTTP 응답에 HSTS 헤더 무시되지만 부정확)
    • sub-domain (예: api.example.com, auth.example.com) 이 모두 HTTPS 지원하는지 확인 후 includeSubDomains 결정
    • preload 등록은 ca-tmpl skeleton 단계에서는 보류 (C5 경고) — production 안정화 후 채택 검토
    • dev 환경 (self-signed cert) 에서 HSTS 비활성 — C3 경고

메모 / Notes

  • RFC 6797 와의 관계: HSTS 자체는 RFC 6797 표준. 본 OWASP cheatsheet 는 RFC 의 운영 권고 보완 (preload 위험, includeSubDomains 권장 등 normative 표준에 없는 운영 가이드).
  • preload 의 운영 위험: 한번 preload list 에 등록되면 제거가 매우 어려움 (브라우저 업데이트 cycle 의존). ca-tmpl 같이 새 skeleton 에서는 max-age 짧게 시작 (예: 5분) 후 점진적 증가 권고.
  • includeSubDomains 함정: 모든 sub-domain 이 HTTPS 를 지원해야 함. 일부 legacy sub-domain 이 HTTP-only 면 includeSubDomains 활성 시 접근 불가.