remove ckeditor - not in use
add more strict default password validators
set Django admin as configurable URL
add nginx HSTS and CSP headers
enable moving from private to unlisted in the PORTAL_WORKFLOW private
on default comments listing, show only comments for public media
in case of a private media, dont expose any unneeded metadata
* Webserver security
* Create vHost dirs during install; link vHost to sites-enabled
* Remove default vHosts during install
* Only generate new DH params when also using real certificates
* Removed duplicate ssl_ecdh_curve