Closed GoogleCodeExporter closed 8 years ago
Well, I had to remove the strict transport security header for an independent
reason (turns out it affects the whole domain, and some of our other pages
don't work in https. Whoops!) and it fixed the problem. So, I'm not sure if the
issue is actually with this package, although I'm still curious why it was
redirecting to the non-secure version. But now you know!
Original comment by karla...@gmail.com
on 3 Jul 2014 at 2:20
That is odd. This could fall into the same category as the IIS feature "Require
SSL". When that is enabled, IIS prevents the request from even reaching this
module. Were you using the OWASP recommended IIS module for strict transport
security?
Original comment by vent...@gmail.com
on 4 Jul 2014 at 2:06
Original comment by vent...@gmail.com
on 24 Aug 2014 at 10:35
Original issue reported on code.google.com by
karla...@gmail.com
on 3 Jul 2014 at 1:22Attachments: