You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As per the discussion #193, step-ca should be able to expose an HTTP port instead of only an HTTPS (or in addition to an HTTPS).
There are situations where the use of HTTPS at the step-ca level is unnecessary or nearly impossible, such as when tls terminating load balancers as used.
If HTTPS is still to be enforced, step could require that either the connection be TLS or that the connection come from a trusted IP and that X-Forwarded-Proto be set to https.
dopey, TheSecMaven, fbartels, alexw19, kriswuollett and 5 morePreterPantdopey, fbartels and jacob-alford