Hi,
A little suggestion here, what about enable, by default or by option, the ability to get HSTS (HTTP Strict Transport Security) on ?
This will bring a new layer in the security when using SSL certificates.
Doing that, Apache header module need to be enabled.
So, what's your opinion on this ?