From 9245388053713e3954ee9a5a90aa78b73e705437 Mon Sep 17 00:00:00 2001 From: Patrick Uiterwijk Date: Mon, 16 Oct 2017 21:47:06 +0000 Subject: [PATCH] Add securityheades to websites Signed-off-by: Patrick Uiterwijk --- roles/httpd/website/tasks/main.yml | 1 + roles/httpd/website/templates/securityheaders.conf | 4 ++++ 2 files changed, 5 insertions(+) create mode 100644 roles/httpd/website/templates/securityheaders.conf diff --git a/roles/httpd/website/tasks/main.yml b/roles/httpd/website/tasks/main.yml index 12bc2333e2..13018d6a7f 100644 --- a/roles/httpd/website/tasks/main.yml +++ b/roles/httpd/website/tasks/main.yml @@ -46,6 +46,7 @@ with_items: - logs - robots + - securityheaders notify: - reload proxyhttpd tags: diff --git a/roles/httpd/website/templates/securityheaders.conf b/roles/httpd/website/templates/securityheaders.conf new file mode 100644 index 0000000000..6712d74881 --- /dev/null +++ b/roles/httpd/website/templates/securityheaders.conf @@ -0,0 +1,4 @@ +Header always set X-Frame-Options "DENY" +Header always set X-Xss-Protection "1; mode=block" +Header always set X-Content-Type-Options "nosniff" +Header always set Referrer-Policy "same-origin"