• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Input SSL It and HSTS Options

LRLD

New Pleskian
Server operating system version
Ubuntu 20
Plesk version and microupdate number
18.0.55
Hi everyone,

the SSL It extension seems to check if you have already enabled OCSP, but it doesn't for HSTS, leaving a warning that security can be improved.
I had to add the HSTS header manually due to the lack of "preload" option when enabling through SSL It.
It would be really nice if we could have a "preload" checkbox like we have for "include subdomains" and "Apply to webmail".
Just a thought.

Kind regards

LD
 

Attachments

  • screenshot.png
    screenshot.png
    123.7 KB · Views: 2
If a website accepts a connection through HTTP and redirects to HTTPS then 'preload' prevents a man-in-the-middle attack as far as I understand, so the feature should not be an optional addon for people to vote for in the hope that one day it might get implemented.

I was also looking at hstspreload.org to check HSTS preload status and eligibility, I have SSL It! > redirect from http to https active and my domain in WP is using www., I added the HSTS manually as LD did.

hstspreload.org error;
Error: `http://domain.co.uk` (HTTP) should immediately redirect to `https://domain.co.uk` (HTTPS) before adding the www subdomain. Right now, the first redirect is to `https://www.domain.co.uk/`. The extra redirect is required to ensure that any browser which supports HSTS will record the HSTS entry for the top level domain, not just the subdomain.

Does anyone know how to resolve this issue?

Thanks in advance
 
Back
Top