ojullien/Apache2.4

The HSTS directive is always set even in non ssl case

ojullien opened this issue · 2 comments

The HTTP Strict Transport Security directives should not be in the server conf but in the ssl vhost.

The HTTP page still sends an HSTS header.

The HSTS directive is still in the conf-available/zzz-ssl.conf file.

My mistake, checking wrong version.