From 850e1605df140a0b52d7bd4c3a1c3567a67699e1 Mon Sep 17 00:00:00 2001 From: rayjlinden <42587610+rayjlinden@users.noreply.github.com> Date: Wed, 12 Jan 2022 13:24:22 -0800 Subject: caddyhttp: Return HTTP 421 for mismatched Host header (#4023) Potential fix for #4017 although the consensus is unclear. Made change to return status code 421 instead of 403 when StrictSNIHost matching is on. --- modules/caddyhttp/server.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'modules/caddyhttp') diff --git a/modules/caddyhttp/server.go b/modules/caddyhttp/server.go index 98fd962..e302c36 100644 --- a/modules/caddyhttp/server.go +++ b/modules/caddyhttp/server.go @@ -302,7 +302,7 @@ func (s *Server) enforcementHandler(w http.ResponseWriter, r *http.Request, next err := fmt.Errorf("strict host matching: TLS ServerName (%s) and HTTP Host (%s) values differ", r.TLS.ServerName, hostname) r.Close = true - return Error(http.StatusForbidden, err) + return Error(http.StatusMisdirectedRequest, err) } } return next.ServeHTTP(w, r) -- cgit v1.2.3