HSTS support
Christopher Bongaarts
cab at umn.edu
Wed Feb 18 12:42:51 EST 2015
On 2/18/2015 11:38 AM, Ian Young wrote:
> I was thinking about supporting HTTP Strict Transport Security on my IdP. I do this elsewhere and it's a fairly simple set-a-header operation in things like Apache.
Main thing keeping me away from it is that it prevents the user from
overriding the SSL warning if you try to connect directly to one server
behind a load balancer and the SSL cert does not contain the "real"
server name.
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the dev
mailing list