HSTS support

Christopher Bongaarts cab at umn.edu
Wed Feb 18 12:42:51 EST 2015


On 2/18/2015 11:38 AM, Ian Young wrote:
> I was thinking about supporting HTTP Strict Transport Security on my IdP. I do this elsewhere and it's a fairly simple set-a-header operation in things like Apache.

Main thing keeping me away from it is that it prevents the user from 
overriding the SSL warning if you try to connect directly to one server 
behind a load balancer and the SSL cert does not contain the "real" 
server name.

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%



More information about the dev mailing list