add hsts headers to all ssl vhosts.#84
add hsts headers to all ssl vhosts.#84cz8s wants to merge 1 commit intoleapcode:masterfrom pixelated:add_hsts
Conversation
Copied from bettercrypto.org
|
This is already being set in: puppet/modules/site_apache/templates/vhosts.d/api.conf.erb: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" I agree that it should be put into the commonly included file, but if we do that, we should remove the existing ones and be sure that common one is included. Also of interest is why some of these have a different max-age? |
|
Having it in common would be nice. Then pixelated could use it. I will update this PR accordingly and find out why we have different TTLs |
|
@cz8s - just wanted to check on the status of this, are you still planning on updating the PR and checking on the different TTLs? |
|
Its on my to do list. But I won't work on this the next weeks. |
|
@cz8s ping, do you still intend to look into this ? |
HSTS header for all users
Copied from bettercrypto.org.