Do you have a guide HSTS with nginx?

It can be easily enabled adding this string at the Nginx config in the server section:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";

SPF/DKIM: The only SPF record I ever wrote was to allow everyone send mail for one of my domains to please outlook.com. What is improved by having only two systems that are allowed to send for lists.osmocom.org?

I think that SPF record will no limit anybody to send mails for lists.osmocom.org, but vice versa.
I wrote about that because sometimes the digests and subscription messages marked as spam.

С наилучшими пожеланиями,
Яницкий Вадим.

2016-02-19 17:36 GMT+06:00 Holger Freyther <holger@freyther.de>:

> On 19 Feb 2016, at 09:08, Вадим Яницкий <axilirator@gmail.com> wrote:
>
> Hi all!
>


> So, my suggestions:
> - Create the main page that will describe all all of the child projects
> of Osmocom umbrella including recent news and plans.
> - Separate the libosmocore related pages from OsmocomBB
> into a new section named "Libraries", for example.
> - Separate both SIMTrace and softSIM into a new sections.

yes, we can have separate projects for them now and should do it. I don't think we can move wiki pages from one project to another but we should be able to somehow add redirects.

I intend to add one more wiki plugin to have table of contents and other features we are used to from trac.



> It it would be nice to enable Strict-Transport-Security to avoid
> some traffic interception attempts. Also what about enabling
> SPF and DKIM for mailing lists?


projects.osmocom.org is using "Let's encrypt". Do you have a guide HSTS with nginx?

SPF/DKIM: The only SPF record I ever wrote was to allow everyone send mail for one of my domains to please outlook.com. What is improved by having only two systems that are allowed to send for lists.osmocom.org?