GaProgMan / OwaspHeaders.Core

Inject OWASP recommended HTTP Headers for increased security in a single line
https://www.nuget.org/packages/OwaspHeaders.Core/
MIT License
282 stars 35 forks source link

Bugfix/expect ct deprecated #78

Closed jamie-taylor-rjj closed 1 year ago

jamie-taylor-rjj commented 1 year ago

Expect-CT has been disabled by default, this is related to the following, which is taken directly from the OWASP Secure Headers Project (as of May 11th, 2023):

Deprecated.

⚠️ Warning: This header will likely become obsolete in June 2021. Since May 2018 new certificates are expected to support SCTs by default. Certificates before March 2018 were allowed to have a lifetime of 39 months, those will all be expired in June 2021.

source: https://owasp.org/www-project-secure-headers/#expect-ct

jamie-taylor-rjj commented 1 year ago

Fixes #72