Bug#824514: Please enable HSTS preloading

2016-05-17 Thread Paul Wise
On Tue, May 17, 2016 at 7:13 AM, Josh Triplett wrote: > https://www.debian.org/ (and other Debian sites) serve a > Strict-Transport-Security header to enable HSTS. Please consider > enabling preloading as well; see https://hstspreload.appspot.com/ Unfortunately we can't do that because they only

Bug#824514: Please enable HSTS preloading

2016-05-16 Thread Josh Triplett
Package: www.debian.org Severity: wishlist https://www.debian.org/ (and other Debian sites) serve a Strict-Transport-Security header to enable HSTS. Please consider enabling preloading as well; see https://hstspreload.appspot.com/ for details. Enabling preloading would ensure that even if a user