HSTS support

Ian Young ian at iay.org.uk
Tue Feb 24 07:06:46 EST 2015


> On 18 Feb 2015, at 17:53, Wilson, Bruce E. <wilsonbe at ornl.gov> wrote:
> 
> To me, that’s more a developer/tester thing than a user thing.  I wouldn’t want a user to _ever_ override a browser certificate warning when going to an IdP.

+1

To me, the "no ignoring cert warnings" part of HSTS seems at least as important as the "no http" part.

Which is not to say I'd want to force HSTS on IdP deployers, but it seems like a useful option to have.

    -- Ian




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20150224/cb2b0fc4/attachment-0001.bin 


More information about the dev mailing list