From 5db790bb30f098238c0655921ef07d45c57633d2 Mon Sep 17 00:00:00 2001 From: Jimmy Zelinskie Date: Fri, 22 May 2015 16:09:11 -0400 Subject: [PATCH] setup-tool: add HSTS info box --- static/directives/config/config-setup-tool.html | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/static/directives/config/config-setup-tool.html b/static/directives/config/config-setup-tool.html index a3a344286..065d55134 100644 --- a/static/directives/config/config-setup-tool.html +++ b/static/directives/config/config-setup-tool.html @@ -98,6 +98,11 @@ A valid SSL certificate and private key files are required to use this option. +
+ Enabling SSL also enables HTTP Strict Transport Security.
+ This prevents downgrade attacks and cookie theft, but browsers will reject all future insecure connections on this hostname. +
+ @@ -841,4 +846,4 @@ - \ No newline at end of file +
Certificate: