What Is HSTS? Take SSL Security One Step Further
· Security
HSTS (HTTP Strict Transport Security) is an HTTP security header that instructs browsers to communicate with the site only via HTTPS for a specified duration. Standardized in RFC 6797 and supported by all modern browsers.
The Problem Without HSTS
Even on an HTTPS site, a user typing http://example.com or clicking an old http:// link sends the first request as plain HTTP. The server redirects to HTTPS (301). But this first HTTP request is vulnerable to SSL Stripping: an attacker intercepts it and maintains an unencrypted connection with the user.
How HSTS Prevents This
With HSTS active, the browser converts http:// requests to https:// internally before they leave the device — based on a previously received directive. The HTTP request never reaches the network, making SSL stripping impossible.
Enabling HSTS
Nginx: add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
Apache: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Directives: max-age (seconds the browser applies the policy; 31536000 = 1 year), includeSubDomains (applies to all subdomains — all must support HTTPS), preload (required to join the HSTS Preload list).
HSTS Preload List
Apply at hstspreload.org to have your site embedded in browsers' built-in HSTS lists. First-time visitors will never send an HTTP request. The list is permanent — removal requires a process — so ensure all subdomains are HTTPS-ready before applying.
Also set the Secure flag on all cookies so they're transmitted only over HTTPS.
Visit the PekiSSL product page to find the right certificate for your needs.