Closed Bug 1312797 Opened 9 years ago Closed 9 years ago

Ramp up HSTS max-age on hg.mozilla.org

Categories

(Developer Services :: Mercurial: hg.mozilla.org, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: gps, Assigned: gps)

References

Details

Attachments

(2 files)

+++ This bug was initially created as a clone of Bug #1312135 +++ We deployed HSTS to hg.mozilla.org in bug 1312135 with a max-age of 5 minutes. We should ramp that up to like 1 year once we're confident HSTS will stick. atoll: what's the usual ramp-up interval?
Flags: needinfo?(rsoderberg)
I would wait a day minimum. Sites with higher uncertainty might wait longer.
Flags: needinfo?(rsoderberg)
Comment on attachment 8804776 [details] hgserver: ramp up HSTS max-age to 1 hour (bug 1312797); https://reviewboard.mozilla.org/r/88672/#review87756 shipit
Attachment #8804776 - Flags: review?(klibby) → review+
Keywords: leave-open
Pushed by gszorc@mozilla.com: https://hg.mozilla.org/hgcustom/version-control-tools/rev/14faf1fd7673 hgserver: ramp up HSTS max-age to 1 hour ; r=fubar
Summary: Ramp us HSTS max-age on hg.mozilla.org → Ramp up HSTS max-age on hg.mozilla.org
We're now at max-age=86400 in production. We'll let that run for a week or two before finalizing on 1 year or some such.
Attachment #8811429 - Flags: review?(klibby) → review+
I deployed the HSTS to 1 year change to production.
Status: ASSIGNED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Removing leave-open keyword from resolved bugs, per :sylvestre.
Keywords: leave-open
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: