Skip to content

Commit

Permalink
Increase HSTS max-age to default to one year (#10564)
Browse files Browse the repository at this point in the history
  • Loading branch information
migg24 authored Oct 27, 2023
1 parent 7e7001d commit 8c3aeaa
Show file tree
Hide file tree
Showing 5 changed files with 5 additions and 5 deletions.
2 changes: 1 addition & 1 deletion docs/user-guide/nginx-configuration/configmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ The following table shows a configuration option's name, type, and the default v
|[http2-max-concurrent-streams](#http2-max-concurrent-streams)|int|128||
|[hsts](#hsts)|bool|"true"||
|[hsts-include-subdomains](#hsts-include-subdomains)|bool|"true"||
|[hsts-max-age](#hsts-max-age)|string|"15724800"||
|[hsts-max-age](#hsts-max-age)|string|"31536000"||
|[hsts-preload](#hsts-preload)|bool|"false"||
|[keep-alive](#keep-alive)|int|75||
|[keep-alive-requests](#keep-alive-requests)|int|1000||
Expand Down
2 changes: 1 addition & 1 deletion internal/ingress/controller/config/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ const (
// that tell browsers that it should only be communicated with using HTTPS, instead of using HTTP.
// https://developer.mozilla.org/en-US/docs/Web/Security/HTTP_strict_transport_security
// max-age is the time, in seconds, that the browser should remember that this site is only to be accessed using HTTPS.
hstsMaxAge = "15724800"
hstsMaxAge = "31536000"

gzipTypes = "application/atom+xml application/javascript application/x-javascript application/json application/rss+xml application/vnd.ms-fontobject application/x-font-ttf application/x-web-app-manifest+json application/xhtml+xml application/xml font/opentype image/svg+xml image/x-icon text/css text/javascript text/plain text/x-component"

Expand Down
2 changes: 1 addition & 1 deletion test/data/cleanConf.expected.conf
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ http {
listen_ports = { ssl_proxy = "442", https = "443" },

hsts = true,
hsts_max_age = 15724800,
hsts_max_age = 31536000,
hsts_include_subdomains = true,
hsts_preload = false,
})
Expand Down
2 changes: 1 addition & 1 deletion test/data/cleanConf.src.conf
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ lua_shared_dict ocsp_response_cache 5M;
listen_ports = { ssl_proxy = "442", https = "443" },

hsts = true,
hsts_max_age = 15724800,
hsts_max_age = 31536000,
hsts_include_subdomains = true,
hsts_preload = false,
})
Expand Down
2 changes: 1 addition & 1 deletion test/data/config.json
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
"gzipTypes": "application/atom+xml application/javascript application/x-javascript application/json application/rss+xml application/vnd.ms-fontobject application/x-font-ttf application/x-web-app-manifest+json application/xhtml+xml application/xml font/opentype image/svg+xml image/x-icon text/css text/javascript text/plain text/x-component",
"hsts": true,
"hstsIncludeSubdomains": true,
"hstsMaxAge": "15724800",
"hstsMaxAge": "31536000",
"keepAlive": 75,
"mapHashBucketSize": 64,
"maxWorkerConnections": 16384,
Expand Down

0 comments on commit 8c3aeaa

Please sign in to comment.