Caddy: Where are SSL options?

Created on 27 Apr 2017  路  2Comments  路  Source: caddyserver/caddy

Hello,

I try to migrating from Nginx to Caddy (0.10), But I dont find SSL options to keep the enable same features.

How to enable _Session resumption_ and _HSTS_ ?

image

Thanks

question

Most helpful comment

For HSTS you can do header / Strict-Transport-Security "max-age=31536000;", see the example here: https://caddyserver.com/docs/header

As for session resumption, it was talked about in this blog post: https://caddyserver.com/blog/caddy-0_8_3-released. I don't know much about this feature so I can't really comment further.

But FYI, questions like this should usually go on the forums if it's not an explicit issue: https://caddy.community/

I'm closing this, but feel free to continue discussing here 馃槃

All 2 comments

For HSTS you can do header / Strict-Transport-Security "max-age=31536000;", see the example here: https://caddyserver.com/docs/header

As for session resumption, it was talked about in this blog post: https://caddyserver.com/blog/caddy-0_8_3-released. I don't know much about this feature so I can't really comment further.

But FYI, questions like this should usually go on the forums if it's not an explicit issue: https://caddy.community/

I'm closing this, but feel free to continue discussing here 馃槃

You don't want session resumption by caching, it's not a great idea for servers to be storing that extra state anyway. If it gets compromised, every other client goes down with it. Session resumption by tickets is simpler and safer.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

ericmdantas picture ericmdantas  路  3Comments

kilpatty picture kilpatty  路  3Comments

lorddaedra picture lorddaedra  路  3Comments

jgsqware picture jgsqware  路  3Comments

billop picture billop  路  3Comments