Strict-Transport-Security does not work
-
Hello,
I use this tool to check security and privacy of my websites
https://webbkoll.dataskydd.net/en/results?url=http%3A%2F%2Fserious-games.at%2F#headers
Although I have this settings in the firewall
Basic Policies:
Enable NinjaFirewall for HTTPS traffic onlyAdvanced Policies:
Set Strict-Transport-Security 1 yearI have got the result:
Strict-Transport-Security NO and a red warningOnly after I have added this into root/.htaccess
<IfModule mod_headers.c> Header set Strict-Transport-Security "max-age=15768000; includeSubDomains" env=HTTPS </IfModule>
I have got the result:
Strict-Transport-Security YES, max-age=31536000, max-age=15768000; includeSubDomainsmax-age=31536000 must be the 1 year
Any idea why the settings in the firewall alone did not work?
Where do you save the information about the 31536000 secondsBest regrads
Jürgen
- The topic ‘Strict-Transport-Security does not work’ is closed to new replies.