Skip to content

Commit 9f464ca

Browse files
authored
Merge pull request #4388 from uyuni-project/proceduresTidyUp
Procedures tidy up
2 parents 4cc54b5 + af43222 commit 9f464ca

File tree

1 file changed

+11
-3
lines changed

1 file changed

+11
-3
lines changed

modules/administration/pages/ssl-certs-hsts.adoc

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,13 @@
66
HTTP Strict Transport Security (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security[HSTS]) is a policy mechanism that helps to protect websites against man-in-the-middle attacks such as protocol downgrade attacks and cookie hijacking.
77

88
On {productname}, HSTS is enabled by default.
9-
If needed, you can disable it on the server following this procedure:
9+
If you need to disable it on the server, follow this procedure:
1010

1111

1212

1313
.Procedure: Disabling HSTS on the server
14+
[role=procedure]
15+
_____
1416
. On the server container host, as root, execute the following command to create a new configuration file with setting [literal]``max-age=0``:
1517
1618
+
@@ -31,10 +33,13 @@ mgrctl exec -- \
3133
mgrctl exec -- systemctl restart apache2
3234
----
3335
36+
_____
3437

35-
To disable it on proxies:
38+
If you need to disable it on the proxy, follow this procedure:
3639

37-
.Procedure: Disabling HSTS on the proxies
40+
.Procedure: Disabling HSTS on the proxy
41+
[role=procedure]
42+
_____
3843
. On the server container host, as root, execute the following command to create a new configuration file with setting [literal]``max-age=0``:
3944
4045
+
@@ -54,6 +59,9 @@ echo 'Header always set Strict-Transport-Security "max-age=0; includeSubDomains'
5459
mgrpxy install podman --tuning-httpd /etc/uyuni/custom-httpd.conf config.tar.gz
5560
----
5661
62+
_____
63+
64+
5765
[WARNING]
5866
====
5967
When naming the new config file [literal]``<filename>.conf``, make sure it is loaded at the right time.

0 commit comments

Comments
 (0)