Re: HSTS handling incorrect

2015-10-04 Thread =JeffH
e that the HSTS Policy applies to HTTP over any TCP port of an HSTS Host. NOTE: In the case where an explicit port is provided (and to a lesser extent with subdomains), it is reasonably likely that there is actually an HTTP (i.e., non-secure) server running on the specified port and that an HTTPS request

fyi: initial draft of "Ciphers in Use in the Internet" is now available

2012-03-08 Thread =JeffH
Of possible interest.. Subject: [Cfrg] Fwd: New Version Notification for draft-irtf-cfrg-cipher-catalog-00.txt From: David McGrew Date: Tue, 6 Mar 2012 07:05:24 -0500 (04:05 PST) To: c...@irtf.org Hi, the initial version of "Ciphers in Use in the Internet" is now available at