


How to enable HTTP Strict Transport Security (HSTS) in Apache?
Jul 13, 2025 am 01:12 AMEnable HSTS to force browsers to access websites via HTTPS, improving security. 1. To enable HTTPS in Apache, you must first configure HTTPS, and then add Strict-Transport-Security response header in the site configuration file or .htaccess; 2. To configure max-age (such as 31536000 seconds), includeSubDomains and preload parameters; 3. Make sure that the mod_headers module is enabled, otherwise run sudo a2enmod headers and restart Apache; 4. You can optionally submit to the HSTS Preload list, but it must meet the conditions such as HTTPS support for both the main site and the subdomain and the header is correct. It is recommended to use SSL Labs SSL Test to test configuration integrity before submitting.
Enable HSTS (HTTP Strict Transport Security) to force the browser to access your website only through HTTPS, improving security. It is not difficult to enable this function in Apache, but you need to have HTTPS configured.
Adding HSTS response header
HSTS is achieved by adding Strict-Transport-Security
to the server response header. In Apache, you can add this header by modifying the site configuration file or .htaccess
file.
Open your Apache site configuration file (such as /etc/apache2/sites-available/example.com.conf
), and then add the following code to the <virtualhost></virtualhost>
block:
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
This configuration means:
-
max-age
: Tells the browser how long it takes to access using HTTPS, in seconds. 31536000 means one year. -
includeSubDomains
: Applicable to all subdomains. -
preload
: means that you want the website to be added to the browser's HSTS preload list (the next steps will talk about whether to submit a preload).
If you are using .htaccess
, you can also add the same statement.
Make sure the mod_headers module is enabled
Header
directive mentioned above depends on Apache's mod_headers
module. If this module is not enabled, the settings will not take effect.
You can use the following command to check whether it is enabled:
sudo a2enmod headers
If you prompt "Module headers already enabled", it means there is no problem. Otherwise, remember to restart Apache after running:
sudo systemctl restart apache2
Submit HSTS Preload List (optional)
If you want your website to be hardcoded into the HSTS list in your browser to prevent HTTP still being used during the first visit, you can apply to join the HSTS Preload List .
But be aware of:
- Once the submission is successful, it cannot be easily revoked.
- Certain conditions must be met, such as both the main site and the
www
subdomain must support HTTPS, and the correct HSTS header must be returned.
Before submitting, it is recommended to test whether your configuration is correct. You can use tools such as SSL Labs SSL Test .
Basically that's it. As long as you ensure that HTTPS is normal, the header is set correctly, and the module is enabled, HSTS will work smoothly.
The above is the detailed content of How to enable HTTP Strict Transport Security (HSTS) in Apache?. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

Software preparation I am using a virtual machine with CentOS-6.6, with the host name repo. Refer to the steps to install a Linux virtual machine in Windows, I installed JDK in that virtual machine, refer to the guide to installing JDK in Linux. In addition, the virtual machine is configured with a key-free login itself, and the settings for configuring key-free login between each virtual machine are referenced. The download address of Hadoop installation package is: https://mirrors.aliyun.com/apache/hadoop/common/. I am using hadoop 2.6.5 version. Upload the Hadoop installation package to the server and unzip [root@repo~]#tarzxv

NGINX and Apache are both powerful web servers, each with unique advantages and disadvantages in terms of performance, scalability and efficiency. 1) NGINX performs well when handling static content and reverse proxying, suitable for high concurrency scenarios. 2) Apache performs better when processing dynamic content and is suitable for projects that require rich module support. The selection of a server should be decided based on project requirements and scenarios.

NGINX is more suitable for handling high concurrent connections, while Apache is more suitable for scenarios where complex configurations and module extensions are required. 1.NGINX is known for its high performance and low resource consumption, and is suitable for high concurrency. 2.Apache is known for its stability and rich module extensions, which are suitable for complex configuration needs.

NGINX and Apache each have their own advantages and disadvantages, and the choice should be based on specific needs. 1.NGINX is suitable for high concurrency scenarios because of its asynchronous non-blocking architecture. 2. Apache is suitable for low-concurrency scenarios that require complex configurations, because of its modular design.

The steps to deploy a Joomla website on PhpStudy include: 1) Configure PhpStudy, ensure that Apache and MySQL services run and check PHP version compatibility; 2) Download and decompress PhpStudy's website from the official Joomla website, and then complete the installation through the browser according to the installation wizard; 3) Make basic configurations, such as setting the website name and adding content.

PHP code can be executed in many ways: 1. Use the command line to directly enter the "php file name" to execute the script; 2. Put the file into the document root directory and access it through the browser through the web server; 3. Run it in the IDE and use the built-in debugging tool; 4. Use the online PHP sandbox or code execution platform for testing.

Updating the Tomcat version in the Debian system generally includes the following process: Before performing the update operation, be sure to do a complete backup of the existing Tomcat environment. This covers the /opt/tomcat folder and its related configuration documents, such as server.xml, context.xml, and web.xml. The backup task can be completed through the following command: sudocp-r/opt/tomcat/opt/tomcat_backup Get the new version Tomcat Go to ApacheTomcat's official website to download the latest version. According to your Debian system

Reasons for system performance not recovered after uninstalling the Apache service may include resource occupancy by other services, error messages in log files, resource consumption by abnormal processes, network connection problems, and file system residues. First, check whether there are other services or processes before uninstalling with Apache; second, pay attention to the operating system's log files and find error messages that may occur during the uninstallation process; second, check the system's memory usage and CPU load, and find out abnormal processes; then, use the netstat or ss command to view the network connection status to ensure that no ports are occupied by other services; finally, clean up the remaining configuration files and log files after uninstallation to avoid occupying disk space.
