Skip to content

Commit 3cf631e

Browse files
Update HTTP Strict Transport Security (HSTS) max-age value
Set to 31536000 as recommended by OWASP.
1 parent f450109 commit 3cf631e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

src/ngx_http_security_headers_module.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -272,9 +272,9 @@ ngx_http_security_headers_filter(ngx_http_request_t *r)
272272
{
273273
ngx_str_set(&key, "Strict-Transport-Security");
274274
if (1 == slcf->hsts_preload) {
275-
ngx_str_set(&val, "max-age=63072000; includeSubDomains; preload");
275+
ngx_str_set(&val, "max-age=31536000; includeSubDomains; preload");
276276
} else {
277-
ngx_str_set(&val, "max-age=63072000; includeSubDomains");
277+
ngx_str_set(&val, "max-age=31536000; includeSubDomains");
278278
}
279279
ngx_set_headers_out_by_search(r, &key, &val);
280280
}

0 commit comments

Comments
 (0)