IE8 HTTPs Download Issue

Posted by Jon Egerton on Pro Webmasters See other posts from Pro Webmasters or by Jon Egerton
Published on 2012-10-15T08:40:42Z Indexed on 2012/10/15 9:50 UTC
Read the original article Hit count: 277

I have a problem with a system I develop related to IE8 downloading over SSL (ie on sites using https://...) and is described on this MS kb article:

http://support.microsoft.com/kb/323308

We use the HTTPCacheability.NoCache option as the data being downloaded is sensitive, and is downloaded from a secured site. I don't want that data to be cached on any of the proxies etc that the response passes through back to the client.

The article describing the issue details a fix to the client side registry changing a BypassSSLNoCacheCheck setting.

I don't want to loosen the system security just for IE8, as the system works fine on anything more upto date. Getting all the clients to apply the hotfix is difficult at best, and impossible at worst. We need to support IE8 in the system, at least for now.

So:

1: Does the detailed hotfix have any implications for the security at the browser end in IE8 - does it mean the file will be cached? (in a place other than where the user saves the file).

2: Is there some way I can get these files downloadable with a change at the server end that doesn't break the security side of things?

© Pro Webmasters or respective owner

Related posts about security

Related posts about ssl