The HSTS directive is always set even in non ssl case
ojullien opened this issue · 2 comments
ojullien commented
The HTTP Strict Transport Security directives should not be in the server conf but in the ssl vhost.
ojullien commented
The HTTP page still sends an HSTS header.
The HSTS directive is still in the conf-available/zzz-ssl.conf file.
ojullien commented
My mistake, checking wrong version.