X-Git-Url: https://git.openstreetmap.org/chef.git/blobdiff_plain/842193c1cb41f57515bb785120c61882eac99de4..8f6bf8b7cd2909565909a6f817426a3f6c8c0d80:/cookbooks/imagery/templates/default/nginx_imagery.conf.erb diff --git a/cookbooks/imagery/templates/default/nginx_imagery.conf.erb b/cookbooks/imagery/templates/default/nginx_imagery.conf.erb index b95bc601f..dcdc28729 100644 --- a/cookbooks/imagery/templates/default/nginx_imagery.conf.erb +++ b/cookbooks/imagery/templates/default/nginx_imagery.conf.erb @@ -31,6 +31,10 @@ server { add_header Strict-Transport-Security "<%= node[:ssl][:strict_transport_security] %>" always; <% end -%> + # Requests sent within early data are subject to replay attacks. + # See: http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_early_data + ssl_early_data on; + root "/srv/<%= @name %>"; gzip on;