view modules/website/templates/https_core_conf.erb @ 157:c6b1b42f3e4b puppet-3.6

Move all sites to separate LetsEncrypt certs to make adding future domains easier
author IBBoard <dev@ibboard.co.uk>
date Thu, 30 Mar 2017 20:41:18 +0100
parents 9cf4ebd6d2ba
children c72d2b5f9be2
line wrap: on
line source

Header always set Strict-Transport-Security "max-age=16070400; includeSubDomains"
Header always set X-Xss-Protection "1; mode=block"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"

RewriteCond %{HTTP_HOST} !=<%= @primary_name %>
RewriteRule ^(.*)$ https://<%= @primary_name %>$1 [R=301,L]