mrisher / smtp-sts

SMTP Strict Transport Security
Apache License 2.0
35 stars 19 forks source link

Specify that 'enforce' also reports in the 'Policy Application' section? #109

Closed lbaudoin closed 8 years ago

lbaudoin commented 8 years ago

When a policy fails and the mode is 'enforce' it seems that we should report the failure as well as fail. An alternative is to have an 'enforce and report' mode.

mrisher commented 8 years ago

Wouldn't this return sts-invalid in the TLSRPT report? Or is there another place you'd like to report this?

lbaudoin commented 8 years ago

Without also reading the TLSRPT RFC it wasn't clear that the STS 'enforce' mode would also report so it might help to mention it in the STS document. It is not a big deal I just thought I'd mention it.

danmarg commented 8 years ago

d6019c5