make HSTS more strict & longer
This commit is contained in:
parent
c77fce86a8
commit
3b66195deb
@ -10,6 +10,6 @@ ssl_dhparam /etc/ssl/certs/dhparam.pem;
|
||||
ssl_stapling on;
|
||||
ssl_stapling_verify on;
|
||||
|
||||
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains" always;
|
||||
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
|
||||
add_header X-Frame-Options DENY;
|
||||
add_header X-Content-Type-Options nosniff;
|
||||
|
Loading…
Reference in New Issue
Block a user