Blocking port 80 dies not matter to auditors. Try as you might, those "educated fellows" will still follow their checklists and ding you for it. Same as not having the "secure" flag set on cookies on HTTPS-only sites.

