Optionally include subdomains in transport security.
This commit is contained in:
parent
61e6de8a06
commit
e538066bf4
|
@ -13,6 +13,8 @@ nginx_org_modules: []
|
|||
# enabled: yes
|
||||
# See https://mozilla.github.io/server-side-tls/ssl-config-generator/
|
||||
nginx_ssl_level: intermediate
|
||||
nginx_strict_transport_security_expire: 15768000
|
||||
nginx_strict_transport_security_include_subdomains: False
|
||||
|
||||
nginx_snippets_dir: /etc/nginx/snippets
|
||||
|
||||
|
|
|
@ -45,5 +45,5 @@ ssl_trusted_certificate {{ letsencrypt_acme_certs_dir }}/fullchain;
|
|||
{% else %}
|
||||
ssl_trusted_certificate {{ nginx_ssl_fullchain_file | default('/etc/nginx/ssl/cacert.crt') }};
|
||||
{% endif %}
|
||||
add_header Strict-Transport-Security max-age=15768000;
|
||||
add_header Strict-Transport-Security "max-age={{ nginx_strict_transport_security_expire }}{% if nginx_strict_transport_security_include_subdomains %}; includeSubdomains{% endif %}";
|
||||
{% endif %}
|
||||
|
|
Loading…
Reference in New Issue