Skip to content
This repository was archived by the owner on Jul 21, 2025. It is now read-only.

Commit 7c52b23

Browse files
committed
Add preloaded-expect-ct.badssl.com
This subdomain serves the Expect-CT header and is on the Chrome preload list for Expect-CT, but does not serve SCTs. Visiting it in Chrome should thus generate and send an Expect-CT report.
1 parent fd8fa65 commit 7c52b23

File tree

3 files changed

+43
-0
lines changed

3 files changed

+43
-0
lines changed
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
---
3+
server {
4+
listen 80;
5+
server_name preloaded-expect-ct.{{ site.domain }};
6+
7+
return 301 https://$server_name$request_uri;
8+
}
9+
10+
server {
11+
listen 443;
12+
server_name preloaded-expect-ct.{{ site.domain }};
13+
14+
include {{ site.serving-path }}/nginx-includes/wildcard.preloaded-expect-ct.conf;
15+
include {{ site.serving-path }}/nginx-includes/tls-defaults.conf;
16+
include {{ site.serving-path }}/common/common.conf;
17+
18+
root {{ site.serving-path }}/domains/cert/preloaded-expect-ct;
19+
}
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
---
2+
subdomain: preloaded-expect-ct
3+
layout: page
4+
favicon: yellow
5+
background: rgb(246, 207, 47)
6+
---
7+
8+
<div id="content">
9+
<h1>
10+
{{ page.subdomain }}.<br>{{ site.domain }}
11+
</h1>
12+
</div>
13+
14+
<div id="footer">
15+
This site is on the Expect CT preload list but does not serve SCTs.
16+
</div>
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
---
2+
---
3+
4+
ssl on;
5+
ssl_certificate {{ site.cert-path }}/wildcard-main.pem;
6+
ssl_certificate_key /etc/keys/leaf-main.key;
7+
8+
add_header Expect-CT preload;

0 commit comments

Comments
 (0)