The Trinity Technology Services system administrators implement changes to Varnish to dramatically improve our Drupal website’s security.

Why have MySQL + PHP do something apache can do?
Why have apache do something that varnish can do?
### TTS Apache Hardening
set resp.http.X-XSS-Protection = "1; mode=block";
set resp.http.Strict-Transport-Security= "max-age=31536000; includeSubDomains";
set resp.http.X-Content-Type-Options = "nosniff";

We inadvertently blocked fourth-level domains

