Changes

Jump to: navigation, search

Security/FirefoxOperations

71 bytes added, 14:06, 18 May 2018
no edit summary
* [ ] Set HSTS to 31536000 (1 year)
* `strict-transport-security: max-age=31536000`
* [ ] If the service is not hosted under `services.mozilla.com`, it must be manually added to [Firefox's preloaded pins](https://dxr.mozilla.org/mozilla-central/source/security/manager/tools/PreloadedHPKPins.json#184). This only applies to production services, not short-lived experiments.
* If service has an admin panels, it must:
* [ ] only be available behind Mozilla VPN (which provides MFA)
Confirm
529
edits

Navigation menu