HTTPS ڻỰ㡢ʾ TLS/SSL Э飬ͨݼܡܷʽӦĴ⣬ݵԡһԣΪûȫ顢õ˽
ȻHTTPS TLS/SSL ֻڣټӦݴҪԳƼܣ˸ս
ΪһõļܹһҪⰲȫ棬κһб࣬Ӱյû顣
ˣΪ˼˰ȫܣȫվ HTTPS 2015 ʼУʱһʱ䣬Ҫϵͳ HTTPS 졢HTTPS Ż HTTPS Ҷ湤û HTTPS ·ܹüΪ˿ܡ
ȫվ HTTPS
2015 꿪ʼ滮 HTTPS ص飬ʱɽϷdz٣վص HTTPS 꾡
ͼȫվ HTTPS
ͼʾֱϵͳ졢ŻͻҶߣ
ϵͳ졣ԭϵͳҪ֧ HTTPSи죬Ҫ HTTPS 㣬Ҳǿͨ 443 ˿ڣеӦϵͳ֧ HTTPS ʡ
ڴ˻ҳԴ滻һ HTTPS ҳ HTTP ʱͻִ⡣£CDN ֤ĴHTTPS ԷҲӭж⡣
Żϵͳ죬 TLS ֣ȻһĿʧȥֲܵʧﵽܺͰȫأŻְŻ㣬Ļϸչ
Ҷߡɽվⲿʱ仨ģHTTPS һߵĹУȿ࣬вǰûзֵ⡣
֤һԽȫվȫȫûһԶѳ HTTPSԸӪ̺ͳмûȥҶߡ
HTTPS ֮ϵͳƪ
01HTTPS 㶨
ϵͳͷȴǿͨ 443 ˿ڣϵͳ CDNӲؾ⡢Ӧ÷ǽWeb Ӧ÷ݲ㡣ѵ·Ҫ HTTPSÿ㶼 SSL 𣿴Ƿġ
ԣӦþ SSL ֣ SSL Ҫǵ HTTPS Ķλ
ͼܹ HTTPS λã
ͼʾǰ HTTPS CDN Ӧϵͳ֮䣬IJ+߲㸺ؾļܹ
IJ㸺ز HTTPS жأҪְ TCP ķַ߲㸺 SSL ֣Ӧϵͳ 80 ˿ڣ൱ HTTPS жصĹ̡
ĺôһ棬ϵͳӦò治ҪΪ HTTPS κεһ棬 HTTPS ĵȡŻöڽɡ
02ҳԴ滻
һ Mixed Content
һҳԣҳ HTTPS أһڲҳԪ HTTP ʣʱ RFC ͻһ Mixed Content
ԣҪһȫ HTTPS ҳ棬ͲӦл HTTP
ڶ// 滻 http://
// 滻 http://ͿҳеԪһ䣬ȥѭԭ
x-request-url Ķʹ
Ȼ//滻ҲһЩӡٸӣͼ¼ϵͳḶ́
ͼʾû authID ʧЧ https://xxx.suning.com/authStatus Ȩжأַͻ HTTP
ҵϵͳȨĻReponse 302 ͻת¼ϵͳʱὫڶҳ¼Ϊԭʼҳ棬صûˣûȥ¼ϵͳ¼ϵͳɼȨԺٻʱ HTTP ַյû MixContent
ˣ x-request-url ⣬ͼ
ԭʼЭ鶼¼ x-request-url УҵϵͳȨһҪѭ x-request-url ¼Э飬ͿӦԻµû Mix Content ⡣