tencent cloud

$0 14-Day TrialExperience EdgeOne for acceleration and security protection!

Feedback

Content Delivery Network

HSTS Configuration

Last updated: 2024-12-30 21:40:54

Configuration Overview

HTTP Strict Transport Security (HSTS) is a web security protocol promoted by the Institution of Electronics and Telecommunication Engineers (IETE). It forces the client (such as a browser) to use HTTPS to create a connection with the server so as to help encrypt the website globally.

Configuration Limitations

expireTime can range from 0 to 365 days and is configured in seconds.
Check includeSubDomain if you need to include sub-domain names.
To enable HSTS configuration, HTTPS acceleration configuration must be completed first.
After the HSTS configuration is enabled, we recommend enable Forced Redirection Configuration to redirect HTTP requests to HTTPS requests. Otherwise the browser will not create HSTS cache for HTTP requests.

Configuration Guide

Log in to the CDN console, select Domain Management on the left sidebar, and click Manage on the right of a domain name to enter its configuration page. Open the HTTPS Configuration tab to find the HSTS Configuration section. It is disabled by default.

Toggle it on and configure accordingly:

Click Confirm to apply the configuration to the response header. You can click Edit to modify it later.



Configuration Sample

If the HSTS configuration of the domain name cloud.tencent.com is as follows:

The response header is:


Contact Us

Contact our sales team or business advisors to help your business.

Technical Support

Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

7x24 Phone Support
Hong Kong, China
+852 800 906 020 (Toll Free)
United States
+1 844 606 0804 (Toll Free)
United Kingdom
+44 808 196 4551 (Toll Free)
Canada
+1 888 605 7930 (Toll Free)
Australia
+61 1300 986 386 (Toll Free)
EdgeOne hotline
+852 300 80699
More local hotlines coming soon