Real-world HSTS experiences

Jarno Huuskonen jarno.huuskonen at uef.fi
Wed Jan 20 03:36:46 EST 2016


Hi,

On Tue, Jan 19, Farmer, Jacob wrote:
> We are planning to enable HSTS[1] for IDP.  Everything I can find suggests there is no adverse impact to doing this, but my support colleagues are understandably a little concerned about it.  Has anyone else gone through the experience of transitioning their IDP to support HSTS?  And if so, any fallout?
> 

We've set HSTS header on our idp for over a year and haven't noticed any
problems. (The idp is accessible only on port 443(https)).

> [1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security

-Jarno

-- 
Jarno Huuskonen


More information about the users mailing list