What Is HSTS? Take SSL Security One Step Further

· Security

HSTS (HTTP Strict Transport Security) is an HTTP security header that instructs browsers to communicate with the site only via HTTPS for a specified duration. Standardized in RFC 6797 and supported by all modern browsers.

The Problem Without HSTS

Even on an HTTPS site, a user typing http://example.com or clicking an old http:// link sends the first request as plain HTTP. The server redirects to HTTPS (301). But this first HTTP request is vulnerable to SSL Stripping: an attacker intercepts it and maintains an unencrypted connection with the user.

How HSTS Prevents This

With HSTS active, the browser converts http:// requests to https:// internally before they leave the device — based on a previously received directive. The HTTP request never reaches the network, making SSL stripping impossible.

Enabling HSTS

Nginx: add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;

Apache: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"

Directives: max-age (seconds the browser applies the policy; 31536000 = 1 year), includeSubDomains (applies to all subdomains — all must support HTTPS), preload (required to join the HSTS Preload list).

HSTS Preload List

Apply at hstspreload.org to have your site embedded in browsers' built-in HSTS lists. First-time visitors will never send an HTTP request. The list is permanent — removal requires a process — so ensure all subdomains are HTTPS-ready before applying.

Also set the Secure flag on all cookies so they're transmitted only over HTTPS.

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts