×ܽá
»ÆÈë¿Ú»á¼ûÎÊÌâËäÈ»²»ÊÇÖÂÃüµÄÄþ¾²Íþв£¬µ«Ëüȷʵ»áÓ°ÏìÓû§ÌåÑéºÍÍøÕ¾µÄÐÅÓþ¡£Í¨¹ýÉîÈëÀí½â»ÆÈë¿Ú»á¼ûµÄÔÒò£¬²¢½ÓÄɸ߼¶½â¾ö²½·¥ºÍʵÓý¨Ò飬Äú¿ÉÒÔÓÐЧµØ?ÖÆÖ¹ÕâÒ»ÎÊÌâµÄ±¬·¢£¬È·±£ÍøÕ¾µÄÄþ¾²ÐÔºÍÎȶ¨ÐÔ¡£ÎÞÂÛÊÇÈ·±£È«Õ¾HTTPS¡¢ÓÅ»¯ÍøÕ¾¼ÓÔØËÙ¶È£¬ÕÕ¾ÉʵÏÖÍêÕûµÄHTTPSÖØ¶¨Ïò£¬Ã¿Ò»¸öϸ½Ú¶¼ÐèÒª×Ðϸ¿´´ý¡£
Ï£Íû±¾ÎÄÌṩµÄÐÅÏ¢ÄÜ×ÊÖúÄú¸üÈ«ÃæµØÓ¦¶Ô»ÆÈë¿Ú»á¼ûÎÊÌ⣬ÌáÉýÍøÕ¾µÄÕûÌåÄþ¾²ÐÔºÍÓû§ÌåÑé¡£
ʲôÊÇ»ÆÈë¿Ú»á¼û
ÎÒÃÇÐèÒªÁ˽âʲôÊÇ»ÆÈë¿Ú»á¼û¡£»ÆÈë¿Ú£¨Ò²³ÆÎª¡°»ÆÉ«¾¯¸æ¡±»ò¡°»ÆÉ«Ìáʾ¡±£©ÊÇä¯ÀÀÆ÷ÔÚ»á¼ûÄ³Ð©ÍøÕ¾Ê±»áÏÔʾµÄ?¾¯¸æÐÅÏ¢¡£Õâͨ³£ÌåÏÖÍøÕ¾´æ?ÔÚDZÔÚµÄÄþ¾²ÎÊÌ⣬ËäÈ»·×Æç¶¨ÊÇÕæÕýµÄÄþ¾²Íþв£¬µ«ÈÔÐèÒªÒýÆð×¢Òâ¡£ÕâÖÖ¾¯¸æ¿ÉÄÜ»áÈÃÓû§¶ÔÍøÕ¾µÄ¿ÉÐŶȱ¬·¢»³ÒÉ£¬½ø¶øÓ°ÏìÍøÕ¾µÄ»á¼ûÁ¿ºÍÓû§ÌåÑé¡£
ʵʩҪÁ죺
ÔÚЧÀÍÆ÷ÏìӦͷÖÐÌí¼ÓCSPÖ¸ÁÀýÈ磺httpContent-Security-Policy:default-src'self';script-src'self'https://trusted.cdn.com;×Ðϸ²âÊԺ͵÷½âCSP¹æÔò£¬ÒÔÖÆÖ¹¶ÔÍøÕ¾Õý³£¹¦Ð§Ôì³ÉÓ°Ïì¡£
SubresourceIntegrity£¨SRI£©SRIÊÇÒ»ÖÖÓÃÓÚÑéÖ¤Íⲿ×ÊÔ´£¨ÈçJavaScriptÎļþ£©ÍêÕûÐÔºÍÕæÊµÐԵļ¼Êõ¡£Í¨¹ýʹÓÃSRI£¬¿ÉÒÔÈ·±£¼ÓÔØµÄ×ÊԴûÓб»¸Ä¶¯£¬´Ó¶øÌá¸ßÄþ¾²ÐÔ¡£
½â¾ö²½·¥£º
¼ì²é²¢¸üÐÂËùÓÐÄÚ²¿Á´½ÓºÍ×ÊÔ´£¬È·±£Ê¹ÓÃHTTPSÐÒ顣ʹÓÃרҵµÄÄþ¾²É󼯹¤¾ß£¬ÈçQualysºÍNessus£¬¼ì²éSSLÖ¤ÊéºÍÆäËûÄþ¾²ÅäÖá£ÓëµÚÈý·½Äþ¾²Ð§ÀÍÏàÖú£¬°´ÆÚ½øÐÐÄþ¾²É¨ÃèºÍÉ󼯡£
½á¹û£ºÍ¨¹ýÒÔÉϲ½·¥£¬¸ÃÍøÕ¾µÄ»ÆÈë¿Ú»á¼ûÎÊÌâ»ñµÃÁËÓÐЧµÄ½â¾ö£¬Óû§ÌåÑé»ñµÃÁËÏÔÖø¸ÄÉÆ£¬Í¬Ê±ÍøÕ¾µÄÐÅÓþÒ²»ñµÃÁËÌáÉý¡£
»ÆÈë¿Ú»á¼ûµÄ³£?¼ûÔÒò
µ£ÐÄ?È«µÄHTTPÁ¬½Ó´ó´ó¶¼ÏÖ´úä¯ÀÀÆ÷ĬÈ϶ÔHTTPS£¨HyperTextTransferProtocolSecure£©½øÐÐÓÅ»¯£¬¶øHTTP£¨HyperTextTransferProtocol£©Ôò»áÏÔʾ»ÆÉ«¾¯¸æ¡£Èç¹ûÄúµÄÍøÕ¾½öÖ§³ÖHTTP£¬Óû§»á¼ûʱ¿ÉÄܻῴµ½»ÆÉ«Èë¿Ú¾¯¸æ¡£
×ܽá
»ÆÈë¿Ú»á¼ûËäÈ»²¢·ÇÖÂÃüµÄÄþ¾²Íþв£¬µ«Ëüȷʵ»áÓ°ÏìÓû§ÌåÑéºÍÍøÕ¾µÄÐÅÓþ¡£Í¨¹ýÁË½â»ÆÈë¿Ú»á¼ûµÄ³£¼ûÔÒò£¬²¢½ÓÄÉÏàÓ¦µÄ½â¾ö²½·¥£¬Äú¿ÉÒÔÓÐЧµØÖÆÖ¹ÕâÒ»ÎÊÌâµÄ±¬·¢£¬È·±£ÍøÕ¾µÄÕý³£ÔËÐкÍÓû§µÄÂúÒâ¶È¡£ÎÞÂÛÊÇÈ·±£È«Õ¾HTTPS¡¢Çå³ý»ìÏýÄÚÈÝ£¬Õվɵ÷½âÄþ¾²Õ½ÂÔ£¬Ã¿Ò»¸öϸ½Ú¶¼ÐèÒª×Ðϸ¿´´ý¡£
Ï£Íû±¾ÎÄÌṩµÄÐÅÏ¢ÄÜ×ÊÖúÄú¸üºÃµØÓ¦¶Ô»ÆÈë¿Ú»á¼ûÎÊÌ⣬ÌáÉýÍøÕ¾µÄ?ÕûÌåÄþ¾²ÐÔºÍÓû§ÌåÑé¡£
¼ÌÐø´ÓµÚ¶þ²¿?·ÖÉîÈë̽ÌÖ»ÆÈë¿Ú»á¼ûµÄÎÊÌ⣬²¢Ìṩ¸ü¶à½â¾ö²½·¥ºÍʵÓý¨Ò飬×ÊÖúÄúÈ«ÃæÁ˽âºÍÓ¦¶ÔÕâÒ»ÎÊÌ⣬½øÒ»²½ÌáÉýÍøÕ¾µÄÄþ¾²ÐÔºÍÓû§ÌåÑé¡£
У¶Ô£º´ÞÓÀÔª(1C0m4pJyqZtPma0S7t9ZFfz4hTykKag)


