GSA / https

The HTTPS-Only Standard for federal domains (M-15-13), and implementation guidance.
https://https.cio.gov
Other
248 stars 87 forks source link

Update guide.md to clarify redirect requirements #224

Closed h-m-f-t closed 7 years ago

h-m-f-t commented 7 years ago

Several federal agencies have requested additional clarity around the requirements for redirect domains. This change is an attempt to make explicit that redirect domains that are currently only serving port 80 must also serve 443 and generally comply with M-15-13.

The change also explains that redirect domains need not (but might want to, especially w/r/t preloading) redirect internally to the https:// version first.