[websec] test

2017-01-20 Thread =JeffH
test ___ websec mailing list websec@ietf.org https://www.ietf.org/mailman/listinfo/websec

Re: [websec] Notes from an HSTS Meetup (Sep. 2016)

2017-01-20 Thread Eric Mill
On Fri, Jan 20, 2017 at 1:52 PM, Anne van Kesteren wrote: > On Fri, Jan 20, 2017 at 7:38 PM, Eric Mill wrote: > > It's a novel approach, and potentially could serve as a model for other > TLDs > > or suffixes -- so if folks have any feedback or suggestions about this > > effort, it'd be welcome

Re: [websec] Notes from an HSTS Meetup (Sep. 2016)

2017-01-20 Thread Anne van Kesteren
On Fri, Jan 20, 2017 at 7:38 PM, Eric Mill wrote: > It's a novel approach, and potentially could serve as a model for other TLDs > or suffixes -- so if folks have any feedback or suggestions about this > effort, it'd be welcome and timely. Is the reverse not possible? Where everything .gov is HST

Re: [websec] Notes from an HSTS Meetup (Sep. 2016)

2017-01-20 Thread Eric Mill
As a follow-up to the part of the notes about .gov, and potentially using the HSTS preload list as a migration pathway -- that's what the .gov domain program (an office of GSA) announced yesterday: https://cio.gov/automatic-https-enforcement-new- executive-branch-gov-domains/ We're using the prel