From: Peter Palfrader Date: Tue, 4 Oct 2016 06:35:52 +0000 (+0200) Subject: raise max-age for HTTP Public Key Pins from 5 min to 1 hour X-Git-Url: https://git.adam-barratt.org.uk/?a=commitdiff_plain;h=5b1ece962a0c28fb280aac2952d44f719c097084;p=mirror%2Fdsa-puppet.git raise max-age for HTTP Public Key Pins from 5 min to 1 hour --- diff --git a/modules/apache2/templates/ssl-key-pins.erb b/modules/apache2/templates/ssl-key-pins.erb index 41cfceaf8..119f8a421 100644 --- a/modules/apache2/templates/ssl-key-pins.erb +++ b/modules/apache2/templates/ssl-key-pins.erb @@ -23,7 +23,7 @@ res << "" if pin_info.size >= 2 then pin_info = pin_info.map{ |x| x.gsub('"', '\"') } - pin_info << "max-age=300" + pin_info << "max-age=3600" pin_str = pin_info.join("; ") res << " Header always set Public-Key-Pins \"#{pin_str}\"" else