HSTS Header Duplication

2015-08-13 Thread Houser, Rick
Some time back, I turned on HSTS for our sites with something like this: Header always set Strict-Transport-Security max-age=### As near as I could tell, everything was working correctly (2.4.12 presently - will be on 2.4.16 shortly). However, one of our development teams recently added a

Re: HSTS Header Duplication

2015-08-13 Thread Nick Kew
On Thu, 13 Aug 2015 20:28:40 + Houser, Rick rick.hou...@jackson.com wrote: Some time back, I turned on HSTS for our sites with something like this: Header always set Strict-Transport-Security max-age=### I think you're misunderstanding mod_headers and the headers structure. In

Re: HSTS Header Duplication

2015-08-13 Thread Eric Covener
On Thu, Aug 13, 2015 at 6:28 PM, Nick Kew n...@webthing.com wrote: On Thu, 13 Aug 2015 20:28:40 + Houser, Rick rick.hou...@jackson.com wrote: Some time back, I turned on HSTS for our sites with something like this: Header always set Strict-Transport-Security max-age=### I think