๐Ÿ”’
blog.cat.ssl

HSTS header: forcing HTTPS

12.05.2025
โ† All articles

HSTS tells browser 'this site is always HTTPS'.

Why

301 redirect isn't enough โ€” first HTTP connection possible (MITM).

Header

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

HSTS Preload List

hstspreload.org โ€” Google list. All browsers know.

Caution

Once enabled โ€” hard to roll back. Test carefully.

Related articles

โญ Wildcard SSL โ€” one certificate for all subdomains ๐Ÿ†“ Let's Encrypt free SSL vs commercial โ€” when to use what ๐Ÿ” SSL validation โ€” Email, HTTP or DNS ๐Ÿ”‘ CSR and private key โ€” essential SSL files
๐ŸŒ Language
๐Ÿ‡บ๐Ÿ‡ฟ O'zbek ๐Ÿ‡บ๐Ÿ‡ฟ ะŽะทะฑะตะบ ๐Ÿ‡ท๐Ÿ‡บ ะ ัƒััะบะธะน ๐Ÿ‡ฌ๐Ÿ‡ง English โœ“