Browse Source

edit hsts configuration

The header must contain the `includeSubDomains` directive.
The header must contain the `preload` directive.
pull/583/head
Guillaume Vincent 3 years ago
parent
commit
3168380ff0
1 changed files with 3 additions and 3 deletions
  1. +3
    -3
      containers/webserver/httpd-ssl.conf

+ 3
- 3
containers/webserver/httpd-ssl.conf View File

@@ -139,7 +139,7 @@ ServerAdmin EMAIL
SSLEngine on
SSLCertificateFile "/usr/local/apache2/conf/CRT_PATH"
SSLCertificateKeyFile "/usr/local/apache2/conf/KEY_PATH"
Header always set Strict-Transport-Security "max-age=63072000"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
</VirtualHost>

<VirtualHost *:443>
@@ -154,7 +154,7 @@ ServerAdmin EMAIL
SSLEngine on
SSLCertificateFile "/usr/local/apache2/conf/CRT_PATH"
SSLCertificateKeyFile "/usr/local/apache2/conf/KEY_PATH"
Header always set Strict-Transport-Security "max-age=63072000"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
</VirtualHost>

<VirtualHost *:443>
@@ -168,5 +168,5 @@ ServerAdmin EMAIL
SSLEngine on
SSLCertificateFile "/usr/local/apache2/conf/CRT_PATH"
SSLCertificateKeyFile "/usr/local/apache2/conf/KEY_PATH"
Header always set Strict-Transport-Security "max-age=63072000"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
</VirtualHost>

Loading…
Cancel
Save