You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
include BOTH setting the HSTS header AND ensuring that ALL connections are made over HTTPS. Setting the HSTS header is simply one line in the config file. It would be good to break these apart more clearly.
The text was updated successfully, but these errors were encountered:
I recommend than instead of giving us a recipe to follow (which does not
apply to host services by the way) to set-up these parameter, you explain
in more details about what HTTPS and HTSP are and the reason that you
suggest that we do this. In other words, why one makes it more secured that
the other? Advantages/Disadvantages?
--
*NOTICE:* This email may contain information which is confidential and/or
subject to legal privilege, and is intended for the use of the named
addressee only. If you are not the intended recipient, you must not use,
disclose or copy any part of this email. If you have received this email by
mistake, please notify the sender and delete this message immediately.
Noting that the two HSTS docs for Apache and NGINX:
https://github.com/InternetSociety/ose-documentation/blob/master/ose-web-hsts-apache.md
https://github.com/InternetSociety/ose-documentation/blob/master/ose-web-hsts-nginx.md
include BOTH setting the HSTS header AND ensuring that ALL connections are made over HTTPS. Setting the HSTS header is simply one line in the config file. It would be good to break these apart more clearly.
The text was updated successfully, but these errors were encountered: