• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

hsts

  1. J

    Question Getting current HSTS setting status via API

    Hi, I'm looking for a way to check via the API (REST or XML) if a domain has HSTS enabled. Either I'm missing it completely or the value is just not available in any call. I know I can set it via "plesk bin extension --call sslit --hsts -enable ...", but what I'm looking for is the current...
  2. M

    Question Global sttings of HSTS via CLI

    Hi, on my plesk admin-web-server I got many many Subscriptions. After a Server Issue I had to backup, but now all subscritions are not resolveable. I tested out why, its something with HSTS. A switch of will make everything fine. So is it possible to switch global all subscriptons on "false" via...
  3. Quinten

    Resolved After clean install one-time login links do not work

    Hello, After setting up a new server with Ubuntu 20 i installed Plesk but after the install the 2 one time login links do not work. The first link leads to: And the second link takes too long to load Anyone have any idea what could be wrong? This has not happend to me yet. I have tried 2...
  4. K

    Issue HSTS issue with www forward

    Hi I have a question / problem with the SSL-IT HSTS implementation. When I test the hosted websites on ssllabs.com, then the result is that HSTS is not configured and OCSP stapling is not active. When I test on hstpreload.org, I get two errors: Error: No HSTS header Response error: No HSTS...
  5. B

    Question HSTS setup for plesk main hostname

    Hi, I've newly setup a plesk server ang used example.com for the hostname example.com has been enrolled in the hstspreload.org When I've tried now to check example.com I got this error Error: No HSTS headerResponse error: No HSTS header is present on the response. Question is, where am I going...
  6. Dukemaster

    Input PLESK reaches the stars with only Nginx + HSTS (390%)

    ONLY NGINX on PLESK without Apache (reverse proxy) Ladies & Gentlemen, Here is the conclusion of the work of all developers, supporters, members: Yes, it's possible, only the ciphers make the difference in the result (%). But in this case more percent means also less compatibility and...
  7. M

    Resolved How to add nginx header for all https sites (but NOT plain http)?

    It seems we shouldn't be adding this in a file in /etc/nginx/conf.d add_header Strict-Transport-Security "max-age=15768000; preload" always; By doing that we're adding it to both http and https and that's something we shouldn't do. I'm doing this and I can assume many others as this was posted...
  8. learning_curve

    Resolved XFrame Options / X-XSS-Protection / X-Content-Type-Options / HSTS

    Until very recently, these four items were neatly applied across all active domains on our server, simply by following the very clear instructions posted by @UFHH01 in the second post on this thread For no reason that we can understand or immediatley fix (!) now they are faiing to be applied :(...
  9. websavers

    Resolved Quick Preview failing due to HTTP/2 (HSTS)

    After enabling HTTP/2 on a server, quick previews fail to function. This is because HTTP/2 requires a TLS channel, thus enforcing HSTS. However the Quick Preview URL does not present a matching certificate, so the TLS connection fails in most modern browsers that try to negotiate over https...
  10. Dukemaster

    Resolved How can I adjust HSTS in Plesk?

    Hello Plesk-friends, Refering to this article by @UFHH01 in How can I adjust HSTS in Plesk?. I use nginx with apache. First part of UFHH01's help worked great. I also enabled http2.0 by HTTP/2 Support in Plesk Everything works great. In SSL Labs I get A, the first two entries have 100% the...
  11. E

    Resolved How can I adjust HSTS in Plesk?

    Hello, I installed ownCloud on my Plesk server. Unfortunately, I denotes ownCloud error like this: "The" Strict Transport Security "HTTP header is not at least" 15552000 "set seconds. To increase security, we recommend enabling HSTS" How can I adjust HSTS in Plesk? I have: Operating...
Back
Top