@rod
'Cos unlike a shared SSL (still the most common implementation)
I sure hope that is not true. Shared SSL Certs should never have been allowed IMHO and we have never provided them for obvious Authentication insecurity. Is that the pea in your mattress; Shared SSLs?


@mc1-8

Notwithstanding the server has built-in and default redirect methods for handling Protocols and next the .htaccess file has its methods, are you advocating a "script" should also have a built-in default method for handling first load Protocol response and any redirection? I can see where that would cause problems for site owners.