Security Basics mailing list archives
R: force https
From: "Blindhorizon" <blindhorizon () tiscali ti>
Date: Tue, 12 Jul 2005 00:11:06 +0200
Hi
you can do a couple of things:
you can erase the application in IIS working on 80 port, so people
can find something only on the 443 port, where the https application works
(with a normal http request they won't found anything)...or you can do
something smarter: on the website using http you can put a web page with a
meta redirecting on the https link you wany all people to use...
Bye
-----Messaggio originale-----
Da: Leon [mailto:roastin () yahoo com]
Inviato: giovedì 7 luglio 2005 16.18
A: security-basics () securityfocus com
Oggetto: force https
Hello,
I have a web-based frontend for an application that users will be accessing.
It can use http or https. I would like to allow only https. This is a more
relaxed company so it will be harder to enforce a management policy (as in
dont do this do this) so I would like to enforce this through the use of
techonlogy. I know i could set a router acl to permit only https to the
server but this seems kind of like a kludge (first off it wont prevent
people on the same subnet from doing what they want). How can I configure
IIS to only except https connections?
Thx,
Leon
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
Current thread:
- force https Leon (Jul 11)
- RE: force https Mike Tierney (Jul 12)
- Re: force https Greg Stiavetti (Jul 13)
- Re: force https Greg Stiavetti (Jul 12)
- Re: force https security (Jul 12)
- R: force https Blindhorizon (Jul 12)
- RE: force https Mutallip ABLIMIT (Jul 12)
- Re: force https Sean M. Duckett (Jul 12)
- Re: force https Steven Matkoski (Jul 12)
- Re: force https Micheal Espinola Jr (Jul 13)
- Re: force https Paul Kurczaba (Jul 13)
- RE: force https Keenan Smith (Jul 18)
- Re: force https Greg Stiavetti (Jul 20)
- Re: force https Ivan C (Jul 20)
- <Possible follow-ups>
- RE: force https Depp, Dennis M. (Jul 12)
- RE: force https Kirk Brady (Jul 13)
- RE: force https Mike Tierney (Jul 12)
