Closed
Bug 1312797
Opened 9 years ago
Closed 9 years ago
Ramp up HSTS max-age on hg.mozilla.org
Categories
(Developer Services :: Mercurial: hg.mozilla.org, defect)
Developer Services
Mercurial: hg.mozilla.org
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: gps, Assigned: gps)
References
Details
Attachments
(2 files)
+++ This bug was initially created as a clone of Bug #1312135 +++
We deployed HSTS to hg.mozilla.org in bug 1312135 with a max-age of 5 minutes. We should ramp that up to like 1 year once we're confident HSTS will stick.
atoll: what's the usual ramp-up interval?
Flags: needinfo?(rsoderberg)
I would wait a day minimum. Sites with higher uncertainty might wait longer.
Flags: needinfo?(rsoderberg)
| Comment hidden (mozreview-request) |
Comment 3•9 years ago
|
||
| mozreview-review | ||
Comment on attachment 8804776 [details]
hgserver: ramp up HSTS max-age to 1 hour (bug 1312797);
https://reviewboard.mozilla.org/r/88672/#review87756
shipit
Attachment #8804776 -
Flags: review?(klibby) → review+
| Assignee | ||
Updated•9 years ago
|
Keywords: leave-open
Pushed by gszorc@mozilla.com:
https://hg.mozilla.org/hgcustom/version-control-tools/rev/14faf1fd7673
hgserver: ramp up HSTS max-age to 1 hour ; r=fubar
Updated•9 years ago
|
Summary: Ramp us HSTS max-age on hg.mozilla.org → Ramp up HSTS max-age on hg.mozilla.org
Pushed by gszorc@mozilla.com:
https://hg.mozilla.org/hgcustom/version-control-tools/rev/8f758b8fb65c
hgserver: ramp up HSTS max-age to 1 day
| Assignee | ||
Comment 6•9 years ago
|
||
We're now at max-age=86400 in production.
We'll let that run for a week or two before finalizing on 1 year or some such.
| Comment hidden (mozreview-request) |
Comment 8•9 years ago
|
||
| mozreview-review | ||
Comment on attachment 8811429 [details]
hgserver: ramp up HSTS to 1 year (bug 1312797);
https://reviewboard.mozilla.org/r/93518/#review93600
Attachment #8811429 -
Flags: review?(klibby) → review+
Pushed by gszorc@mozilla.com:
https://hg.mozilla.org/hgcustom/version-control-tools/rev/1af87f1ccc18
hgserver: ramp up HSTS to 1 year ; r=fubar
| Assignee | ||
Comment 10•9 years ago
|
||
I deployed the HSTS to 1 year change to production.
Status: ASSIGNED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Comment 11•8 years ago
|
||
Removing leave-open keyword from resolved bugs, per :sylvestre.
Keywords: leave-open
You need to log in
before you can comment on or make changes to this bug.
Description
•