{"id":717,"date":"2017-09-16T11:46:34","date_gmt":"2017-09-16T02:46:34","guid":{"rendered":"http:\/\/manatails.net\/blog\/?p=717"},"modified":"2022-04-03T13:48:54","modified_gmt":"2022-04-03T04:48:54","slug":"disabling-hsts-on-pfsense-webconfigurator","status":"publish","type":"post","link":"https:\/\/manatails.net\/blog\/2017\/09\/disabling-hsts-on-pfsense-webconfigurator\/","title":{"rendered":"Disabling HSTS on pfSense webconfigurator"},"content":{"rendered":"<p>For some time HSTS has been a stupid way to deter people from doing what they have no idea of doing, and now pfSense forces the use of HSTS on its webconfigurator, effectively making all port forwarded secure connections difficult to reach. Stubborn pfSense devs refuse to make an option to disable it, but here is a way to do it.<\/p>\n<ol>\n<li>Enable SSH and open \/etc\/inc\/system.inc<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-718\" src=\"https:\/\/manatails.net\/blog\/wp-content\/uploads\/2017\/09\/2017-09-16-11_29_34-router.home_.mananet.net-PuTTY.png\" alt=\"2017-09-16 11_29_34-router.home.mananet.net - PuTTY\" width=\"857\" height=\"473\" srcset=\"https:\/\/manatails.net\/blog\/wp-content\/uploads\/2017\/09\/2017-09-16-11_29_34-router.home_.mananet.net-PuTTY.png 857w, https:\/\/manatails.net\/blog\/wp-content\/uploads\/2017\/09\/2017-09-16-11_29_34-router.home_.mananet.net-PuTTY-300x166.png 300w, https:\/\/manatails.net\/blog\/wp-content\/uploads\/2017\/09\/2017-09-16-11_29_34-router.home_.mananet.net-PuTTY-768x424.png 768w, https:\/\/manatails.net\/blog\/wp-content\/uploads\/2017\/09\/2017-09-16-11_29_34-router.home_.mananet.net-PuTTY-672x372.png 672w, https:\/\/manatails.net\/blog\/wp-content\/uploads\/2017\/09\/2017-09-16-11_29_34-router.home_.mananet.net-PuTTY-842x465.png 842w\" sizes=\"auto, (max-width: 857px) 100vw, 857px\" \/><\/p>\n<p>2. Remove add_header Strict-Transport-Security line.<\/p>\n<p>3. Reboot the machine, only restarting webconfigurator won&#8217;t work.<\/p>\n<p>&nbsp;<\/p>\n<p>Now you can host other secure connections with peace of mind.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For some time HSTS has been a stupid way to deter people from doing what they have no idea of doing, and now pfSense forces the use of HSTS on its webconfigurator, effectively making all port forwarded secure connections difficult to reach. Stubborn pfSense devs refuse to make an option to disable it, but here &hellip; <a href=\"https:\/\/manatails.net\/blog\/2017\/09\/disabling-hsts-on-pfsense-webconfigurator\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Disabling HSTS on pfSense webconfigurator<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[117],"class_list":["post-717","post","type-post","status-publish","format-standard","hentry","category-computer","tag-pfsense"],"_links":{"self":[{"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/posts\/717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/comments?post=717"}],"version-history":[{"count":2,"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/posts\/717\/revisions"}],"predecessor-version":[{"id":962,"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/posts\/717\/revisions\/962"}],"wp:attachment":[{"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/media?parent=717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/categories?post=717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/manatails.net\/blog\/wp-json\/wp\/v2\/tags?post=717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}