Securing Lighttpd - Moblog
# disable version number display
server.tag = "lighttpd"
# disable IP logging
accesslog.format = "127.0.0.1 %V %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\""
server.modules += ("mod_setenv")
setenv.add-response-header = (
# require ssl for all subdomains
"Strict-Transport-Security" => "max-age=31556926;includeSubDomains",
# don't allow external content at all (new in FF4)
"X-Content-Security-Policy" => "allow 'self'"
)
permalink -
-
http://moblog.wiredwings.com/archives/20110323/Securing-Lighttpd.html