Details
-
Improvement
-
Status: Closed
-
Normal
-
Resolution: Fixed
-
None
-
None
-
None
Description
The current implementation of the seamless https support includes having the JAAS login over https when the page you originally requested is marked as "https/secured".
There's use cases where this is not desired and only the login itself should go over https:
- there are no predefined sections requiring https (www.onehippo.org)
- high volume sites (SSL overhead)
- sites where SSL is not offloaded (caching strategies are affected)
Attachments
Issue Links
- relates to
-
HSTTWO-2727 Support container login to work seamlessly with HST https support
- Closed
-
HSTTWO-3147 By default have a /login over HTTPS setup
- Closed