🔒
blog.cat.ssl

HSTS header: forcing HTTPS

12.05.2025
← All articles

HSTS tells browser 'this site is always HTTPS'.

Why

301 redirect isn't enough — first HTTP connection possible (MITM).

Header

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

HSTS Preload List

hstspreload.org — Google list. All browsers know.

Caution

Once enabled — hard to roll back. Test carefully.

Related articles

📱 SSL pinning: the strongest defense against MITM attacks in mobile apps 🤝 SSL handshake process: the inner mechanics of TLS negotiation step by step 🔓 HTTPS padlock disappeared: causes and step-by-step fixes ⏰ Monitoring SSL certificate expiry: alert services and automation tools
🌐 Language
🇺🇿 O'zbek 🇺🇿 Ўзбек 🇷🇺 Русский 🇬🇧 English ✓