Hi,
I'd like to know how i check if in my Plesk 12.5.30 #60 (Centos 7) Header HSTS is enabled.
I used let's encrypt to encrypt my sites and i added this configuration in Apache & nginx settings:
Additional Apache directives for HTTP
<IfModule mod_rewrite.c>
RewriteEngine on
RewriteCond %{HTTPS} !=on
RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301]
</IfModule>
Additional Apache directives for HTTPS
<IfModule mod_headers.c>
Header set X-XSS-Protection "1; mode=block"
Header set X-Frame-Options "SAMEORIGIN"
SetEnv modHeadersAvailable true
Header always set Strict-Transport-Security "max-age=15768000; includeSubDomains; preload"
</IfModule>
when i try to test them with www.ssllabs.com i get a Overall Rating A but read:
Strict Transport Security (HSTS) No
HSTS Preloading Not in: Chrome Edge Firefox IE
Thank you!
Luca
I'd like to know how i check if in my Plesk 12.5.30 #60 (Centos 7) Header HSTS is enabled.
I used let's encrypt to encrypt my sites and i added this configuration in Apache & nginx settings:
Additional Apache directives for HTTP
<IfModule mod_rewrite.c>
RewriteEngine on
RewriteCond %{HTTPS} !=on
RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301]
</IfModule>
Additional Apache directives for HTTPS
<IfModule mod_headers.c>
Header set X-XSS-Protection "1; mode=block"
Header set X-Frame-Options "SAMEORIGIN"
SetEnv modHeadersAvailable true
Header always set Strict-Transport-Security "max-age=15768000; includeSubDomains; preload"
</IfModule>
when i try to test them with www.ssllabs.com i get a Overall Rating A but read:
Strict Transport Security (HSTS) No
HSTS Preloading Not in: Chrome Edge Firefox IE
Thank you!
Luca