How to ensure Sitecore all traffic is serverd over SSL/TLS.

Update Web.config add following configuration:

    <httpCookies httpOnlyCookies="true" requireSSL="true" lockItem="true" />

This configuration:

  1. Ensures that cookies are secure across your site
  2. Ensures that a client-side script cannot read the cookies
  3. Prevents any additional configuration from overriding these settings.

