Skip to content

Conversation

ktdreyer
Copy link
Contributor

It's easy for users to accidentally set GssapiSSLonly to "Off" in production, or instruct other users to turn this "Off" without understanding the consequences.

Advise users that they should always use HTTPS in production.

It's easy for users to accidentally set GssapiSSLonly to "Off" in
production, or instruct other users to turn this "Off" without
understanding the consequences.

Advise users that they should always use HTTPS in production.
@ktdreyer ktdreyer force-pushed the warn-gssapi-ssl-only branch from b66370f to 77e144a Compare April 16, 2020 23:28
Copy link
Contributor

@simo5 simo5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@simo5 simo5 merged commit dedf84d into gssapi:master Apr 17, 2020
@ktdreyer ktdreyer deleted the warn-gssapi-ssl-only branch April 17, 2020 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants