为什么SPDY在Nginx 1.4.3中打破’Vary:Accept-Encoding’?

我使用SPDY模块从源代码编译了Nginx 1.4.3.



--with-http_ssl_module --prefix=/usr


user  Nginx;
worker_processes  1;

error_log  /var/log/Nginx/error.log warn;
pid        /var/run/Nginx.pid;

events {
    worker_connections  1024;

http {
    include       /etc/Nginx/mime.types;
    default_type  application/octet-stream;

    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/Nginx/access.log  main;

    sendfile        on;
    #tcp_nopush     on;

    keepalive_timeout  65;

    #Compression Settings
    gzip on;
    gzip_http_version 1.0;
    gzip_comp_level 2;
    gzip_proxied any;
    gzip_min_length  1100;
    gzip_buffers 16 8k;
    gzip_types text/plain text/css application/x-javascript text/xml application/xml application/xml+RSS text/javascript image/svg+xml;
    # Some version of IE 6 don't handle compression well on some mime-types,# so just disable for them
    gzip_disable "MSIE [1-6].(?!.*SV1)";
    # Set a vary header so downstream proxies don't send cached gzipped 
    # content to IE6
    gzip_vary on;

    proxy_cache_path /var/www/Nginx_cache levels=1:2 keys_zone=qnx-cache:10m inactive=24h max_size=1g;
    proxy_temp_path /var/www/Nginx_cache/tmp;

    server_tokens off;

    include /etc/Nginx/conf.d/*.conf;

    map $geo $mapping {
        default default;
        US US;
        DE DE;
    CA CA;
    GB GB;
    geo $geo {
        default default;
        include geo.conf;
    upstream default.backend {
#   sticky;
    upstream mysite.backend {
        sticky name=servIDTrack hash=sha1;
        server weight=10 max_fails=3 fail_timeout=10s;
        server weight=10 max_fails=3 fail_timeout=10s;
        server weight=10 max_fails=3 fail_timeout=10s;
server {
        listen      80;
        server_name secure.mysite.com;
        return 301 https://$server_name$request_uri;
server {
        listen 443 ssl;
        server_name secure.mysite.com;
        more_set_headers    "Server: X-Nginx/v1.1 [LB01]";

        ssl_certificate     /etc/Nginx/ssl/secure_mysite_com_ssl.cert;
        ssl_certificate_key /etc/Nginx/ssl/secure_mysite_com_ssl.key;

        ssl_protocols           SSLv3 TLSv1 TLSv1.1 TLSv1.2;
#       ssl_ciphers             RC4:HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers on;
        keepalive_timeout       120;
        ssl_session_cache       builtin:1000 shared:SSL:10m;
        ssl_session_timeout     10m;

        location / {
            proxy_pass http://mysite.backend;
            proxy_set_header        Host            $host;
            proxy_set_header        X-Real-IP       $remote_addr;
            proxy_set_header        X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_redirect          off;
            proxy_http_version      1.1;

            add_header Strict-Transport-Security "max-age=31556926; includeSubdomains";

    # Cache
                proxy_cache qnx-cache;
                proxy_cache_valid  200 301 302  120m;
                proxy_cache_valid 404 1m;
                add_header X-Cache-Status $upstream_cache_status;
                proxy_cache_key "$scheme$host$request_uri";



url: mypage.PHP (SPDY enabled)

HTTP/1.1 200 OK
cache-control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
content-encoding: gzip
content-type: text/html; charset=utf-8
date: Wed,20 Nov 2013 13:39:30 GMT
expires: Thu,19 Nov 1981 08:52:00 GMT
pragma: no-cache
server: X-Nginx/v1.1 [LB01]
status: 200
strict-transport-security: max-age=31556926; includeSubdomains
version: HTTP/1.1
x-cache-status: MISS

url: mypage.PHP (SPDY disabled)

HTTP/1.1 200 OK
Date: Wed,20 Nov 2013 13:45:00 GMT
Content-Type: text/html; charset=utf-8
transfer-encoding: chunked
Connection: keep-alive
vary: Accept-Encoding
Expires: Thu,19 Nov 1981 08:52:00 GMT
Cache-Control: no-store,pre-check=0
Pragma: no-cache
Server: X-Nginx/v1.1 [LB01]
Strict-Transport-Security: max-age=31556926; includeSubdomains
X-Cache-Status: MISS
content-encoding: gzip

url: mystyle.css (SPDY enabled)

HTTP/1.1 200 OK
date: Wed,20 Nov 2013 12:53:49 GMT
content-encoding: gzip
last-modified: Mon,18 Nov 2013 22:09:32 GMT
server: X-Nginx/v1.1 [LB01]
x-cache-status: HIT
strict-transport-security: max-age=31556926; includeSubdomains
content-type: text/css
status: 304
expires: Wed,18 Dec 2013 22:42:35 GMT
cache-control: max-age=2592000
version: HTTP/1.1

url: mystyle.css (SPDY disabled)

HTTP/1.1 200 OK
Date: Wed,20 Nov 2013 13:45:01 GMT
Content-Type: text/css
transfer-encoding: chunked
Connection: keep-alive
vary: Accept-Encoding
Last-Modified: Mon,18 Nov 2013 22:09:32 GMT
Cache-Control: max-age=2592000
Expires: Wed,18 Dec 2013 22:10:13 GMT
Server: X-Nginx/v1.1 [LB01]
Strict-Transport-Security: max-age=31556926; includeSubdomains
X-Cache-Status: HIT
content-encoding: gzip



SPDY(和HTTP / 2.0)要求用户代理支持压缩,并且无法使用vary:Accept-Encoding标头.这就是Nginx删除标题的原因.


Nginx (engine x) 是一个高性能的HTTP和反向代理服务,也是一...
本地项目配置 1 复制 luffy/settings/dev.py为prop.py 修改l...
nginx不仅可以隐藏版本信息,还支持自定义web服务器信息 先看...
一 、此次漏洞分析 1 nginx HTTP/2漏洞 [nginx-announce] ng...
###进入nginx 目录cd /usr/local/nginx###递归显示 2 级目录...
在cmd命令窗口输入下面命令进行查看 tasklist /fi "ima...