Bug#824514: Please enable HSTS preloading

Paul Wise <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <CAKTje6HSpNjYo+ENPfDQOkbG-KDKR=6_WZEgjrOXm0XZdaoYdQ__48065.3275772513$1463471307$gmane$org@mail.gmail.com>
On Tue, May 17, 2016 at 7:13 AM, Josh Triplett wrote:

> https://www.debian.org/ (and other Debian sites) serve a
> Strict-Transport-Security header to enable HSTS.  Please consider
> enabling preloading as well; see https://hstspreload.appspot.com/

Unfortunately we can't do that because they only allow top-level
domains to be preloaded and not all debian.org subdomains support
https (and some never will, like nossl.people.debian.org). If that
requirement were to be relaxed then we could get added to the preload
list.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.