Skip to main content

2025 年 6 月 20 日

Host Checking

To frustrate host injection attacks, the Host header in each incoming request is checked against a list of expected host names.

Note: This topic applies to Horizon 8 versions 2306 and later, 2212.1 and later, 2209.1 and later, and 2111.2 and later.

In earlier releases of Horizon 8, this protection was deactivated by default. To manually deactivate Host Checking, add the entry allowUnexpectedHost=true tolocked.properties.

The list of expected host names includes the External URL (also known as the Secure Tunnel External URL), therefore direct connections to that name, as well as connections through a gateway configured to forward to that name, require no further configuration.

For additional expected names, as well as how to extend the list to load balancers, non-rewriting gateways and alternative canonical names, see see Origin Checking.

此頁面對您有幫助嗎?

針對本主題提供意見回饋

本主題對您有幫助嗎?

請勿填寫任何個人或機密資訊。

正在產生連結…