I want to allow underscore( _ ) https header in load balancer

0

The default setting for load balancer does not allow underscore. But I want to allow this. What should I do?

Thank you

질문됨 일 년 전434회 조회
2개 답변
0

Hi there,

I understand that you want to know if there a way to override the "Drop Invalid header fields" ALB attribute to allow headers containing Underscore in them.

Unfortunately, there is no current ability for the ALB to consider underscore character as valid, and thus no option will be able to override this attribute if routing.http.drop_invalid_header_fields.enabled is set to true.

Although there is a workaround which will allow you to pass the headers with underscores.

You can set routing.http.drop_invalid_header_fields.enabled to false and ensure routing.http.desync_mitigation_mode is in DEFENSIVE mode.

The only limitation here is that, it allows invalid headers to pass, while desync_mitigation_mode ensures desync suspected requests doesn't share connection.

Desync mitigation is invented by ELB and goal is to protect weak target servers and underscore character is one of them that leads to confusion to some target servers that we protect.

Kind Regards,

Ahmad

profile pictureAWS
답변함 일 년 전
0

Hi, may I know will there be any future enhancements to allow underscores in ALB ?

답변함 10일 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠