Forum Discussion
Redirect URL to different hostname after SSL offloading
It depends on what you're redirecting to and why. Let's start with a simple example where you own both sites, under a single domain (ex. web1.domain.com, web2.domain.com) and either of the applications deploys domain cookies. A redirect from the HTTPS to HTTP site will potentially transmit that (session) cookie in the clear to the HTTP site. I'm assuming chells2 isn't simply redirecting to some external non-affiliated site (ex. Google), but rather some other site within the larger organization, or affiliate organization. In which case you should be very worried about what information is available in the clear and how an attacker can take advantage of that unencrypted channel. It probably begs some clarification of intentions, but I see this use case far more often than I'd hope.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
