Pārlūkot izejas kodu

Update _hsts.conf template

I propose the change to max-age value of HSTS from 1 year to 2 years.
David Dosoudil 4 gadi atpakaļ
vecāks
revīzija
1c64252015
1 mainītis faili ar 3 papildinājumiem un 3 dzēšanām
  1. 3 3
      backend/templates/_hsts.conf

+ 3 - 3
backend/templates/_hsts.conf

@@ -1,8 +1,8 @@
 {% if certificate and certificate_id > 0 -%}
 {% if ssl_forced == 1 or ssl_forced == true %}
 {% if hsts_enabled == 1 or hsts_enabled == true %}
-  # HSTS (ngx_http_headers_module is required) (31536000 seconds = 1 year)
-  add_header Strict-Transport-Security "max-age=31536000;{% if hsts_subdomains == 1 or hsts_subdomains == true -%} includeSubDomains;{% endif %} preload" always;
+  # HSTS (ngx_http_headers_module is required) (63072000 seconds = 2 years)
+  add_header Strict-Transport-Security "max-age=63072000;{% if hsts_subdomains == 1 or hsts_subdomains == true -%} includeSubDomains;{% endif %} preload" always;
+{% endif %}
 {% endif %}
 {% endif %}
-{% endif %}