From ce1f2fb1320ac33a26cae925bd42cfeff441d838 Mon Sep 17 00:00:00 2001 From: Felix Stupp Date: Tue, 13 Aug 2019 02:26:06 +0200 Subject: [PATCH] nginx/application: Increased time for HSTS --- roles/nginx/application/templates/https.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/roles/nginx/application/templates/https.conf b/roles/nginx/application/templates/https.conf index 1b3e7b5..cfb1f8d 100644 --- a/roles/nginx/application/templates/https.conf +++ b/roles/nginx/application/templates/https.conf @@ -1,3 +1,3 @@ include {{ nginx_snippets_directory }}/ssl; -add_header Strict-Transport-Security 'max-age=15768000; includeSubDomains; preload;'; # default max age: 2592000 = 30 * 24 * 60 * 60s +add_header Strict-Transport-Security 'max-age=63115200; includeSubDomains; preload'; add_header 'Referrer-Policy' 'same-origin';