
Jump to: navigation, search


8 bytes added, 11:52, 29 September 2016
no edit summary
<source lang:markdown>
Risk Management
* [ ] The service must have performed a Rapid Risk Assessment and have a Risk Record bug (**SVC-RRA**).
* [ ] Set HSTS to 31536000 (1 year) (**INFRA-HSTS**)
* [ ] Set HPKP to 5184000 (60 days) (**INFRA-HPKP**)
* `Public-Key-Pins: max-age=300; pin-sha256="WoiWRyIOVNa9ihaBciRSC7XHjliYS9VwUGOIud4PB18="; pin-sha256="r/mIkG3eEpVdm+u/ko/cwxzOMo1bk4TyHIlByibiA5E="; report-uri="/__hpkpreport__";`
* Start with max-age set to 5 minutes and increase gradually
* Pin to the EV and DV roots of Digicert
* Set a reporting endpoint [ ] If the service is not hosted under `/` , it must be manually added to catch violations in nginx ([example confFirefox's preloaded pins](
* If service has an admin panels, it must:
* [ ] only be available behind Mozilla VPN (which provides MFA) (**INFRA-ADMINVPN**)

Navigation menu