Corrected Syntax on STS
authorshotty1 <shotty1@users.noreply.github.com>
Sat, 12 Apr 2014 17:16:34 +0000 (19:16 +0200)
committershotty1 <shotty1@users.noreply.github.com>
Sat, 12 Apr 2014 17:16:34 +0000 (19:16 +0200)
Syntax was missing "" for STS including subdomains.
Tested with Apache 2.2.22 against OpenSSL 1.0.1e, Debian Wheezy

src/configuration/Webservers/Apache/default-ssl

index 7371287..0428e9f 100644 (file)
        Header add Strict-Transport-Security "max-age=15768000"
        # If you want to protect all subdomains, use the following header
        # ALL subdomains HAVE TO support HTTPS if you use this!
-       # Strict-Transport-Security: max-age=15768000 ; includeSubDomains
+       # Strict-Transport-Security: "max-age=15768000 ; includeSubDomains"
        SSLCipherSuite 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA'
 
 </VirtualHost>