diff --git a/roles/nginx/application/templates/https.conf b/roles/nginx/application/templates/https.conf index 1b3e7b5..cfb1f8d 100644 --- a/roles/nginx/application/templates/https.conf +++ b/roles/nginx/application/templates/https.conf @@ -1,3 +1,3 @@ include {{ nginx_snippets_directory }}/ssl; -add_header Strict-Transport-Security 'max-age=15768000; includeSubDomains; preload;'; # default max age: 2592000 = 30 * 24 * 60 * 60s +add_header Strict-Transport-Security 'max-age=63115200; includeSubDomains; preload'; add_header 'Referrer-Policy' 'same-origin';