HTTP Strict Transport Security (HSTS) Approved as Proposed Standard RFC
As I’d noted back in July, the draft HSTS spec was in IETF-wide last call, from which we exited in August with various helpful comments. We applied summore elbow grease to the ol’spec and shipped it to the IESG (Internet Engineering Steering Group) for further inspection, received more good comments, subsequently applied more tweaks and polish, and voila(!), this morning we have this little missive in our email…
PS: The Wikipedia HSTS entry has a consolidated specification history as well as information regarding implementation and deployment.