Finalizing the HTTPS-Only Standard as formal policy by konklone · Pull Request #108 · GSA/https

@konklone

* Incorporate integrity mention into Goal paragraph more tersely.
* Remove privacy mention from SNI paragraph, since the concern is
  described earlier in the memo ("What HTTPS Doesn't Do"), and is
  now incorporated into the SNI document this paragraph links to.
* Remove description of HTTPS config issues for third party
  content from Mixed Content paragraph. HTTPS resources from third
  parties is no longer "mixed content", and is better handled in
  the guidance. Added a link to the guidance page for Mixed
  Content.
* Edit Security Considerations paragraph on mixed content page to
  describe the issue as "third party content" (since the content
  is no longer mixed) and to emphasize that these considerations
  are not *introduced* by HTTPS, but are rather still present
  under HTTPS (though the situation is much improved).