Skip to content
GitLab
Projects
Groups
Snippets
/
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Menu
Open sidebar
Pleroma
pleroma
Commits
e4bd5a69
Commit
e4bd5a69
authored
Nov 11, 2018
by
kaniini
Browse files
example configs: kill STS/CT headers
parent
df72978d
Pipeline
#4397
passed with stages
in 6 minutes and 42 seconds
Changes
4
Pipelines
1
Hide whitespace changes
Inline
Side-by-side
installation/caddyfile-pleroma.example
View file @
e4bd5a69
...
...
@@ -21,11 +21,6 @@ example.tld {
ciphers ECDHE-ECDSA-WITH-CHACHA20-POLY1305 ECDHE-RSA-WITH-CHACHA20-POLY1305 ECDHE-ECDSA-AES256-GCM-SHA384 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-ECDSA-AES128-GCM-SHA256 ECDHE-RSA-AES128-GCM-SHA256
}
header / {
Strict-Transport-Security "max-age=31536000; includeSubDomains;"
Expect-CT "enforce, max-age=2592000"
}
# If you do not want to use the mediaproxy function, remove these lines.
# To use this directive, you need the http.cache plugin for Caddy.
cache {
...
...
installation/pleroma-apache.conf
View file @
e4bd5a69
...
...
@@ -34,9 +34,6 @@ CustomLog ${APACHE_LOG_DIR}/access.log combined
SSLCompression
off
SSLSessionTickets
off
# Uncomment this only after you get HTTPS working.
# Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
RewriteEngine
On
RewriteCond
%{
HTTP
:
Connection
}
Upgrade
[
NC
]
RewriteCond
%{
HTTP
:
Upgrade
}
websocket
[
NC
]
...
...
installation/pleroma.nginx
View file @
e4bd5a69
...
...
@@ -60,9 +60,6 @@ server {
client_max_body_size 16m;
location / {
# Uncomment this only after you get HTTPS working.
# add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
...
...
installation/pleroma.vcl
View file @
e4bd5a69
...
...
@@ -119,8 +119,3 @@ sub vcl_pipe {
set
bereq.http.connection
=
req.http.connection
;
}
}
sub
vcl_deliver
{
# Uncomment this only after you get HTTPS working.
# set resp.http.Strict-Transport-Security= "max-age=31536000; includeSubDomains";
}
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment