diff --git a/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf index c7109a16a6..cb7969e2a7 100644 --- a/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf +++ b/roles/download/files/httpd/dl.fedoraproject.org/securityheaders.conf @@ -3,3 +3,4 @@ Header always set X-Xss-Protection "1; mode=block" Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "same-origin" Header always set Content-Security-Policy "default-src 'none'" +Header always add Strict-Transport-Security "max-age=31536000; preload"