Finalizing the HTTPS-Only Standard as formal policy by konklone · Pull Request #108 · GSA/https
* Incorporate integrity mention into Goal paragraph more tersely.
* Remove privacy mention from SNI paragraph, since the concern is
described earlier in the memo ("What HTTPS Doesn't Do"), and is
now incorporated into the SNI document this paragraph links to.
* Remove description of HTTPS config issues for third party
content from Mixed Content paragraph. HTTPS resources from third
parties is no longer "mixed content", and is better handled in
the guidance. Added a link to the guidance page for Mixed
Content.
* Edit Security Considerations paragraph on mixed content page to
describe the issue as "third party content" (since the content
is no longer mixed) and to emphasize that these considerations
are not *introduced* by HTTPS, but are rather still present
under HTTPS (though the situation is much improved).