[HTTPS-E Rulesets] "([^/:@]*)\."

Osama Khalid osamak at gnu.org
Fri Jul 8 16:28:22 PDT 2011


This pattern can be seen in many rules. It caused a couple of troubles
lately for Amazon S3 and Netflix (those are just the ones that were
reported)

Since most of the time only one level is covered (ie a.example.com but
not b.a.example.com) because the wildcard "*" in certificate domains
means only one level, I suggest replacing it in all rules with
"([^/:@\.]+)\." and the old rule can be restored when we are sure that
all 2nd+ rules are covered.

--Osama Khalid
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 836 bytes
Desc: not available
URL: <http://lists.eff.org/pipermail/https-everywhere-rules/attachments/20110709/c899e5b3/attachment.sig>


More information about the HTTPS-Everywhere-Rules mailing list