Showing posts with label https. Show all posts
Showing posts with label https. Show all posts
Friday, 9 October 2026
What is HSTS?
HSTS is HTTP Strict Transport Security. This is a web security policy defined under RFC6797 forcing browsers to use HTTPS only. This protects users from attacks like protocol-downgrade and cookie hijacking.
Friday, 31 July 2026
Understanding HTTP Redirects
Introduction
One of these concepts is HTTP redirects. What are they, why do they exist, and what a "reasonable" number of redirects looks like when sending an HTTP request to a server.
What is a redirect - technically speaking?
First the technical part. HTTP redirects occur when a server responds to a client request with the reply 3XX (status code). This is coupled with a location header of the URL it wants the client to load instead.
The browser or other HTTP client (which could be a Python program, for example) then follows the redirect, issuing a new request to the URL in the location header.
Why are they needed?
Examples:
301 Permanent redirect - e.g. for site reorganization, domain migration, SEO link preservation
Also temporary redirects - e.g. for load balancing
HTTP to HTTPS redirect
Redirects can be configure in Apache .htaccess and in nginx.
Pythons requests module allows by default 30 redirects.
Labels:
apache,
http,
httpredirects,
https,
nginx,
Python,
webprogramming
Saturday, 18 July 2026
Revisiting Port 443
Port 443 is primarily known for handling HTTPS traffic over TCP, enabling secure communication between browsers and servers.
It can be used with UDP in specific scenarios like QUIC (for lower latency secure communications) and HTTP/3.
When diagnosing why an HTTPS connection is failing, an in depth knowledge of port 443 is needed.
Subscribe to:
Posts (Atom)