[
https://issues.apache.org/jira/browse/TS-1668?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13864457#comment-13864457
]
James Peach commented on TS-1668:
---------------------------------
I agree that this needs to be per-remap or per-certificate. Documenting how to
do this with an existing plugin is a great start. Direct support in
{{records.config}} or {{ssl_multicert.config}} would be preferable in the
medium term; it's just easier to manage that way.
> Traffic Server does currently not implement HSTS
> ------------------------------------------------
>
> Key: TS-1668
> URL: https://issues.apache.org/jira/browse/TS-1668
> Project: Traffic Server
> Issue Type: Bug
> Components: Security, SSL
> Reporter: Igor Galić
> Fix For: 6.0.0
>
>
> Apache Traffic Server can be used as Reverse Proxy as well as for {{TLS}}
> ({{SSL}}) Termination for a huge number of sites.
> As such is the ideal point to implement [HTTP Strict Transport
> security|http://tools.ietf.org/html/rfc6797].
> I propose enable administrators to globally ({{records.config}}) configure
> HSTS for all sites that offer both, HTTP and HTTPS. (This switch, if
> backported, should default to off for stable releases.)
> We should further also make it possible to disable this setting per-site
> ({{ssl_multicert.config}}).
--
This message was sent by Atlassian JIRA
(v6.1.5#6160)