Re: [websec] Regarding RFC 6797

2018-05-08 Thread Eric Mill
ive for everyone. -- Eric > > -- > https://annevankesteren.nl/ > > ___ > websec mailing list > websec@ietf.org > https://www.ietf.org/mailman/listinfo/websec > > -- Eric Mill Senior Advisor, Technology Transformation Services Federal Acquisition Service,

Re: [websec] Question regarding RFC 6797: What is the proper reading of §8.3 #5

2018-03-01 Thread Eric Mill
ll have to offer all "real" services on other > port with https - with the exception of a "https-bumper" on 80. > > [1] https://tools.ietf.org/html/rfc6797#section-8.3 > > Thanks for any insight, > > Lars > > > *** Lesen. Hören. Wissen. Deutsche Na

Re: [websec] Notes from an HSTS Meetup (Sep. 2016)

2017-01-20 Thread Eric Mill
On Fri, Jan 20, 2017 at 1:52 PM, Anne van Kesteren wrote: > On Fri, Jan 20, 2017 at 7:38 PM, Eric Mill wrote: > > It's a novel approach, and potentially could serve as a model for other > TLDs > > or suffixes -- so if folks have any feedback or suggestions about this >

Re: [websec] Notes from an HSTS Meetup (Sep. 2016)

2017-01-20 Thread Eric Mill
share >> notes eventually though I don't know if they're ready for consumption >> yet. >> >> On Tue, Nov 15, 2016 at 4:08 AM, John Wilander >> wrote: >> > Hi WebAppSec! >> > >> > I know there was an HSTS meetup in San Francisco o