I've been doing my development using http, due to laziness. However, I thought I had set up HSTS on production, and I hadn't, which is one (but only one!) of the reasons craftpoker.com does so poorly on Mozilla's security scan (#1323). So, my plan is to set up certificates for localhost before fixing the scan issues so that we can use HSTS both in production and locally.
Set up certificates for localhost.
I've been doing my development using http, due to laziness. However, I thought I had set up HSTS on production, and I hadn't, which is one (but only one!) of the reasons craftpoker.com does so poorly on Mozilla's security scan (#1323). So, my plan is to set up certificates for localhost before fixing the scan issues so that we can use HSTS both in production and locally.