X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/a87b5d01314ca96a7b26a219cfb0fb17c3e0bba5..709c582dd58742d3a1ba083f9105efdb17a5de6e:/cookbooks/imagery/templates/default/nginx_imagery.conf.erb diff --git a/cookbooks/imagery/templates/default/nginx_imagery.conf.erb b/cookbooks/imagery/templates/default/nginx_imagery.conf.erb index b95bc601f..dcdc28729 100644 --- a/cookbooks/imagery/templates/default/nginx_imagery.conf.erb +++ b/cookbooks/imagery/templates/default/nginx_imagery.conf.erb @@ -31,6 +31,10 @@ server { add_header Strict-Transport-Security "<%= node[:ssl][:strict_transport_security] %>" always; <% end -%> + # Requests sent within early data are subject to replay attacks. + # See: http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_early_data + ssl_early_data on; + root "/srv/<%= @name %>"; gzip on;