• Hi, Pleskians! We are running a UX testing of our upcoming product intended for server management and monitoring.
    We would like to invite you to have a call with us and have some fun checking our prototype. The agenda is pretty simple - we bring new design and some scenarios that you need to walk through and succeed. We will be watching and taking insights for further development of the design.
    If you would like to participate, please use this link to book a meeting. We will sent the link to the clickable prototype at the meeting.
  • (Plesk for Windows):
    MySQL Connector/ODBC 3.51, 5.1, and 5.3 are no longer shipped with Plesk because they have reached end of life. MariaDB Connector/ODBC 64-bit 3.2.4 is now used instead.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Input SSL It and HSTS Options

LRLD

New Pleskian
Server operating system version
Ubuntu 20
Plesk version and microupdate number
18.0.55
Hi everyone,

the SSL It extension seems to check if you have already enabled OCSP, but it doesn't for HSTS, leaving a warning that security can be improved.
I had to add the HSTS header manually due to the lack of "preload" option when enabling through SSL It.
It would be really nice if we could have a "preload" checkbox like we have for "include subdomains" and "Apply to webmail".
Just a thought.

Kind regards

LD
 

Attachments

  • screenshot.png
    screenshot.png
    123.7 KB · Views: 3
If a website accepts a connection through HTTP and redirects to HTTPS then 'preload' prevents a man-in-the-middle attack as far as I understand, so the feature should not be an optional addon for people to vote for in the hope that one day it might get implemented.

I was also looking at hstspreload.org to check HSTS preload status and eligibility, I have SSL It! > redirect from http to https active and my domain in WP is using www., I added the HSTS manually as LD did.

hstspreload.org error;
Error: `http://domain.co.uk` (HTTP) should immediately redirect to `https://domain.co.uk` (HTTPS) before adding the www subdomain. Right now, the first redirect is to `https://www.domain.co.uk/`. The extra redirect is required to ensure that any browser which supports HSTS will record the HSTS entry for the top level domain, not just the subdomain.

Does anyone know how to resolve this issue?

Thanks in advance
 
Back
Top