make HSTS more strict & longer

This commit is contained in:
6543 2021-10-05 01:13:52 +02:00
parent c77fce86a8
commit 3b66195deb
Signed by: 6543
GPG Key ID: C99B82E40B027BAE

View File

@ -10,6 +10,6 @@ ssl_dhparam /etc/ssl/certs/dhparam.pem;
ssl_stapling on;
ssl_stapling_verify on;

add_header Strict-Transport-Security "max-age=15768000; includeSubDomains" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;