hstspreload.org
hstspreload.org copied to clipboard
Cannot add an IPv6-only site
I'd like to add the site https://neběží.xyz (https://xn--neb-tma3u8u.xyz) to the HSTS preload list. This site is intentionally accessible only over IPv6.
When I submit the preload request via https://hstspreload.appspot.com/?domain=neb%C4%9B%C5%BE%C3%AD.xyz I get this error response:
Error: Cannot connect using TLS We cannot connect to https://xn--neb-tma3u8u.xyz using TLS ("Get https://xn--neb-tma3u8u.xyz: dial tcp [2001:1528:132:70::ebe2]:443: connect: network is unreachable").
I can't reproduce this using a local copy of the submission server locally, so I'm guessing this is a Google Cloud limitation.
Here is the output of hstspreload +d "xn--neb-tma3u8u.xyz"
Checking domain xn--neb-tma3u8u.xyz for preload requirements... Observed header: max-age=31536000; includeSubDomains; preload
Warning:
- Unnecessary HSTS header over HTTP [redirects.http.useless_header] The HTTP page at http://xn--neb-tma3u8u.xyz sends an HSTS header. This has no effect over HTTP, and should be removed.
Would you mind fixing the warning and then emailing me at the hstspreload contact address? I'm happy to add you manually.
(xn--neb-tma3u8u.xyz is will be added with Chrome 53.)
Reopening this because we still can't scan IPv6-only sites on Google Cloud.
I've filed a Google-internal bug about this (b/38325009).
i had such problem do Not use VPN it will be fixed اجاره خودرو
I have the same problem with two domains. This needs to get fixed but i will email @Igarron for manual addition.
Any updates on this?
The problem is still not solved. IPv6 should at least be supported as well as IPv4 nowadays.
still not fixed, any updates?
I can't help debug this, since I don't have access to the Google Cloud project. @nharper, would you be able to configure something like this? https://cloud.google.com/compute/docs/ip-addresses/configure-ipv6-address
It looks like those instructions apply only to GCE resources, and don't apply to app engine flex (I can't configure GAE flex VMs). The internal bug is still open for tracking this issue, and now that GCE supports dual-stack, that should help that bug make progress.
This is still an issue. I'm unable to check the preload status of my own IPv6-only site (yartys.no) at hstspreload.org.
I have same problem with my IPv6 only https://ipv6kungen.se. I have made some more sites IPv6-only but they are preloaded already, what happes with them then? I fixed ipv6kungen.se by added an A RR and removed it after. :)