Skip to content

Update HSTS preloading recommendation in hardening section of the admin manual #4779

@lgarron

Description

@lgarron

An article on your site contains a recommended HSTS header value that includes preload in the only example: https://docs.nextcloud.com/server/9/admin_manual/configuration_server/harden_server.html

This is going to shoot developers in the foot, and also doesn't guarantee preloading unless someone submits the site to hstspreload.org separetely. See https://hstspreload.org/#opt-in (and chromium/hstspreload.org#68)
Could you update your guide to remove it, or list two examples, the second of which explains preloading and links to hstspreload.org?

(I tried pinging at https://twitter.com/Nextclouders/status/805161033975398400 and emailing the contact address on your site, but that hasn't resulted in a response over the last 6 months.)

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions