# HG changeset patch # User Kim Alvefur # Date 1372437001 -7200 # Node ID 356e38c7254da0f2ced9ab92107fcea7c7828273 # Parent 1861f3e1e9ffa01f64785b11983a253d1807d592 mod_strict_https: Add page diff -r 1861f3e1e9ff -r 356e38c7254d mod_strict_https.wiki --- /dev/null Thu Jan 01 00:00:00 1970 +0000 +++ b/mod_strict_https.wiki Fri Jun 28 18:30:01 2013 +0200 @@ -0,0 +1,24 @@ +#summary HTTP Strict Transport Security + += Introduction = + +This module implements [https://tools.ietf.org/html/rfc6797 HTTP Strict Transport Security] +and responds to all non-HTTPS requests with a `301 Moved Permanently` redirect to the HTTPS +equivalent of the path. + += Configuration = + +Add the module to the `modules_enabled` list and optionally configure the specific header sent. + +{{{ + modules_enabled = { + ... + "strict_https"; + } + hsts_header = "max-age=31556952" +}}} + += Compatibility = +||trunk||Works|| +||0.9||Works|| +||0.8||Doesn't work||