[
https://issues.apache.org/jira/browse/OFBIZ-9242?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15894346#comment-15894346 ]
Jacques Le Roux commented on OFBIZ-9242:
----------------------------------------
Thanks Wai,
I checked HSTS works perfectly well on trunk and stable demo (ie you are redirected to HTTPS)
http://demo-trunk.ofbiz.apache.org/partymgrhttp://demo-stable.ofbiz.apache.org/partymgrI'll fill
https://hstspreload.org/. Locally we should only use HTTPS with 8443
If you really want to use
http://localhost:8080/partymgr instead of
https://localhost:8443/partymgr simply put 8443 in port.https property. You will maybe face a certificate warning depending of your browser or config.
My idea is to help OFBiz users to use HTTPS+HSTS+letsencrypt on their server by demonstrating how to on OFBiz demos, all come for free!
At least as long as letsencrypt will be sustainable, sounds good for now:
https://letsencrypt.org/sponsors/--
This message was sent by Atlassian JIRA
(v6.3.15#6346)