Skip to main content

2026년 4월 20일

Host Checking

To frustrate host injection attacks, the Host header in each incoming request is checked against a list of expected host names.

Note: This topic applies to Horizon 8 versions 2306 and later, 2212.1 and later, 2209.1 and later, and 2111.2 and later.

In earlier releases of Horizon 8, this protection was deactivated by default. To manually deactivate Host Checking, add the entry allowUnexpectedHost=true tolocked.properties.

The list of expected host names includes the External URL (also known as the Secure Tunnel External URL), therefore direct connections to that name, as well as connections through a gateway configured to forward to that name, require no further configuration.

For additional expected names, as well as how to extend the list to load balancers, non-rewriting gateways and alternative canonical names, see see Origin Checking.

이 페이지가 도움이 되었나요?

이 항목에 대한 피드백 보내기

이 항목이 도움이 되었나요?

개인정보나 기밀정보는 입력하지 마세요.

링크를 생성하는 중…