Firefox HSTS Settings store
So I've set HSTS on whole domain with subdomains, preloaded, cosmic max-age, like:
Strict-Transport-Security "max-age=63072000; includeSubdomains; preload"
And now Firefox forces HTTPS on every subdomain. Even if I enter http:// directly into address bar.
Changing HSTS to:
Strict-Transport-Security "max-age=3600"
doesn't help because previous one is somehow cached for very long time.
Clearing cache and history doesnt help either, firefox still stores it somewhere. On clear profile everything is working OK.
So there is this file in your Firefox profile directory called SiteSecurityServiceState.txt.
Turn off Firefox so there's nothing using your profile directory and edit that file, remove your site from cache.
Archives
- February 2016
- October 2015
- September 2015
- July 2013
- June 2013
- April 2013
- March 2013
- December 2011
- November 2011
- July 2011
- June 2011
- February 2010
- September 2009
- March 2009
- February 2009