{"id":390,"date":"2022-10-28T11:00:00","date_gmt":"2022-10-28T11:00:00","guid":{"rendered":"https:\/\/cheapsslweb.com\/resources\/?p=390"},"modified":"2025-12-10T10:53:17","modified_gmt":"2025-12-10T10:53:17","slug":"what-is-hsts-certificate","status":"publish","type":"post","link":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate","title":{"rendered":"What is HTTP Strict Transport Security? How to Enable HSTS?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In this article, you will learn what an HSTS certificate is, how to implement HSTS, and a step-by-step guide on how HSTS <a href=\"https:\/\/cheapsslweb.com\/blog\/what-is-ssl-stripping\/\">stops SSL stripping attacks<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gone are the days when only an <em>https:\/\/ <\/em>connection was enough to secure your website and provide confidence in your security to your customers. Today, hackers have found vulnerabilities in SSL connections, such as the infamous 301 redirect that lets them destroy the safety of an SSL connection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This may make you feel unsafe the next time you try banking online, but fortunately, we have invented a solution. HSTS connections are even more secure than basic HTTP connections for several reasons. Before diving deeper into this topic, we\u2019ll review the basics of how standard HTTPS kept you secure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is HSTS Encryption?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When you want to keep your information private on the internet, using a secret code can boost your chances of preventing third parties from reading it. This can be done using encryption, which completely scrambles your message to prevent both humans and machines from being able to make sense of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When your message reaches the destination, the receiver can use a key to unscramble it in a process known as decryption. Currently, encryption is done in two ways \u2013 <a href=\"https:\/\/cheapsslweb.com\/blog\/symmetric-encryption-vs-asymmetric-encryption\">symmetric vs asymmetric encryption.<\/a><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Symmetric Encryption<\/strong><\/td><td><strong>Asymmetric Encryption<\/strong><\/td><\/tr><tr><td>Symmetric Encryption uses a single key for encryption and decryption. This key is shared over an unsecured network.<\/td><td>Asymmetric Encryption uses separate key pairs of encrypting keys(public keys) and decrypting keys(private keys) for both parties. The private keys are never shared.<\/td><\/tr><tr><td>It is faster but less secure.<\/td><td>It Is extremely secure but quite slow.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see, <a href=\"https:\/\/cheapsslweb.com\/blog\/what-is-symmetric-key-encryption\/\">symmetric encryption<\/a> has one obvious vulnerability, which lets an attacker intercept the key before the connection is encrypted. While not so obvious, <a href=\"https:\/\/cheapsslweb.com\/blog\/what-is-asymmetric-encryption-how-does-it-work\/\">asymmetric encryption<\/a> can also be quite vulnerable to interception. While the attacker may not be able to access the private key, they can get access to the public key in this case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using the public key, the attacker could encrypt malicious code and send it to the client, making it seem like it came from the server. This could include anything from <a href=\"https:\/\/cheapsslweb.com\/blog\/what-is-spyware-and-spyware-examples\/\">spyware<\/a> to ransomware. Fortunately, there is a way to determine each communication&#8217;s authenticity over a secured network.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is the Purpose of HSTS?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">HSTS (HTTP Strict Transport Security) is a web security mechanism that tells browsers: Always use HTTPS when connecting to this site\u2014never use HTTP. This helps ensure secure, encrypted connections and protects users from man-in-the-middle (MITM) and Stripping attacks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are HSTS and HTTPS Same?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No, HSTS and HTTPS are not the same, though they are related in below term:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HTTPS is a protocol that encrypts communication between a browser and a website using TLS. Where as HSTS is a security policy that a website sends to the browser using an HTTP header. HTTPS can exist without HSTS but HSTS requires HTTPS to function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read:<\/strong> <a href=\"https:\/\/cheapsslweb.com\/resources\/what-is-the-hsts-preload-list-for-chrome-how-to-add-domain-to-the-hsts-preload-list\">What is the HSTS Preload List for Chrome? How to Add Domain to HSTS Preload List?<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Vulnerability<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability this system presents isn\u2019t very complicated. Simply put, websites need time to establish an <a href=\"https:\/\/cheapsslweb.com\/blog\/ssl-tls-handshake-explained-process-work-and-importance\/\">SSL handshake<\/a>, and during that brief period, they connect to their clients using an <em>http:\/\/<\/em> connection. This leaves the connection vulnerable to attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Exploits of this vulnerability include sending phishing login pages to the client by redirection or even stripping an SSL connection while leaving the connection unsecured and unencrypted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Fix the HSTS Error in Chrome?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">HSTS stands for HTTP Strict Transport Security, and it isn\u2019t a new technology. It was invented back in 2012, but it has taken a long time to implement fully. This policy prevents websites from accepting any HTTP connections at all, thereby directly connecting with their clients using HTTPS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read:<\/strong> <a href=\"https:\/\/cheapsslweb.com\/resources\/how-to-fix-the-hsts-missing-from-https-server-error\">How To Fix the HSTS Missing from HTTPS Server Error?<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In general, browsers try to connect to websites using HTTP; however, this gets changed thanks to HSTS, which sends instructions to browsers to adhere to HTTPS connections only strictly. While this still leaves you vulnerable the first time you connect to the website, it can be delivered via HTTPS to ensure maximum security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Implement HSTS?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Implementing HSTS requires an SSL certificate. In the case of several subdomains on your website, you would need a Wildcard Certificate, but in other cases, just about any <a href=\"https:\/\/cheapsslweb.com\">cheap SSL certificate<\/a> would work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Once you have the certificate, you can implement HSTS with the following code:<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">For Apache Web Server<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><em># Use HTTP Strict Transport Security to force client to use secure connections only <\/em><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;VirtualHost 192.168.1.1:443>  \n  Header always set Strict-Transport-Security \"max-age=31536000; includeSubDomains\"  \n&lt;\/VirtualHost><\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">For lighttpd<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code><em>server.modules += ( \"mod_setenv\" ) $HTTP&#91;\"scheme\"] == \"https\" { setenv.add-response-header = (\"Strict-Transport-Security\" =&gt; \"max-age=300; includeSubDomains; preload\") }<\/em><\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">For NGINX<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code><em>add_header Strict-Transport-Security 'max-age=300; includeSubDomains; preload; always;'<\/em><\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">For IIS Servers<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code><em>protected void Application_BeginRequest(Object sender, EventArgs e) { switch (Request.Url.Scheme) { case \"https\": Response.AddHeader(\"Strict-Transport-Security\", \"max-age=31536000; includeSubDomains; preload\"); break; case \"http\": var path = \"https:\/\/\" + Request.Url.Host + Request.Url.PathAndQuery; Response.Status = \"301 Moved Permanently\"; Response.AddHeader(\"Location\", path); break; } }<\/em><\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read:<\/strong> <a href=\"https:\/\/cheapsslweb.com\/blog\/how-to-disable-hsts-settings-in-chrome-firefox\/\">How to Disable HSTS in Chrome &amp; Firefox?<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While it has been in use for over a decade, HSTS has become necessary for making the World Wide Web a more secure place. Implement it on your website today for maximum security for your users.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this article, you will learn what an HSTS certificate is, how to implement HSTS, and a step-by-step guide on how HSTS stops SSL stripping attacks. Gone are the days when only an https:\/\/ connection was enough to secure your website and provide confidence in your security to your customers. Today, hackers have found vulnerabilities<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":417,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[389],"tags":[390,392,391],"class_list":["post-390","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ssl-and-encryption","tag-hsts-certificate","tag-hsts-encryption","tag-http-strict-transport-security-hsts","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HTTP Strict Transport Security: How to Implement or Enable HSTS<\/title>\n<meta name=\"description\" content=\"Know what is HSTS certificate, how to implement or enable HSTS and a step-by-step guide know on how HSTS stops SSL stripping attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HTTP Strict Transport Security: How to Implement or Enable HSTS\" \/>\n<meta property=\"og:description\" content=\"Know what is HSTS certificate, how to implement or enable HSTS and a step-by-step guide know on how HSTS stops SSL stripping attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate\" \/>\n<meta property=\"og:site_name\" content=\"CheapSSLWeb.com Resources\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cheapsslweb\" \/>\n<meta property=\"article:published_time\" content=\"2022-10-28T11:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-10T10:53:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/10\/what-is-hsts-certificate.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"621\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cheapsslweb\" \/>\n<meta name=\"twitter:site\" content=\"@cheapsslweb\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#\\\/schema\\\/person\\\/c7d26eacacd9392c23be9d82e9af145e\"},\"headline\":\"What is HTTP Strict Transport Security? How to Enable HSTS?\",\"datePublished\":\"2022-10-28T11:00:00+00:00\",\"dateModified\":\"2025-12-10T10:53:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate\"},\"wordCount\":826,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/what-is-hsts-certificate.jpg\",\"keywords\":[\"HSTS Certificate\",\"HSTS Encryption\",\"HTTP Strict Transport Security (HSTS)\"],\"articleSection\":[\"SSL and Encryption\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate\",\"url\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate\",\"name\":\"HTTP Strict Transport Security: How to Implement or Enable HSTS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/what-is-hsts-certificate.jpg\",\"datePublished\":\"2022-10-28T11:00:00+00:00\",\"dateModified\":\"2025-12-10T10:53:17+00:00\",\"description\":\"Know what is HSTS certificate, how to implement or enable HSTS and a step-by-step guide know on how HSTS stops SSL stripping attacks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#primaryimage\",\"url\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/what-is-hsts-certificate.jpg\",\"contentUrl\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/what-is-hsts-certificate.jpg\",\"width\":960,\"height\":621,\"caption\":\"What is HSTS?\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/what-is-hsts-certificate#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is HTTP Strict Transport Security? How to Enable HSTS?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#website\",\"url\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/\",\"name\":\"CheapSSLWeb.com\",\"description\":\"SSL Errors and Installation Tutorials\",\"publisher\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#organization\"},\"alternateName\":\"Cheap SSL Web\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#organization\",\"name\":\"CheapSSLWeb\",\"alternateName\":\"Cheap SSL Web\",\"url\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/logo.png\",\"contentUrl\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/logo.png\",\"width\":177,\"height\":60,\"caption\":\"CheapSSLWeb\"},\"image\":{\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/cheapsslweb\",\"https:\\\/\\\/x.com\\\/cheapsslweb\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/cheapsslweb\\\/\",\"https:\\\/\\\/www.pinterest.com\\\/cheapsslweb\\\/\",\"https:\\\/\\\/www.instagram.com\\\/cheapsslweb\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/#\\\/schema\\\/person\\\/c7d26eacacd9392c23be9d82e9af145e\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcheapsslweb.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fjanki-mehta-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcheapsslweb.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fjanki-mehta-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcheapsslweb.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fjanki-mehta-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a Cyber-Security Enthusiast having 7+ years of experience and knowledge about Encryption, Digital Certificates and Online Security, She helps online users to stay safe and protect their online presence. Explore SSL Errors, Installation Guide and Security Tutorials for Safe Browsing and Web Security Experience.\",\"sameAs\":[\"https:\\\/\\\/cheapsslweb.com\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/pw-jankimehta\\\/\"],\"url\":\"https:\\\/\\\/cheapsslweb.com\\\/resources\\\/author\\\/janki-mehta\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HTTP Strict Transport Security: How to Implement or Enable HSTS","description":"Know what is HSTS certificate, how to implement or enable HSTS and a step-by-step guide know on how HSTS stops SSL stripping attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate","og_locale":"en_US","og_type":"article","og_title":"HTTP Strict Transport Security: How to Implement or Enable HSTS","og_description":"Know what is HSTS certificate, how to implement or enable HSTS and a step-by-step guide know on how HSTS stops SSL stripping attacks.","og_url":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate","og_site_name":"CheapSSLWeb.com Resources","article_publisher":"https:\/\/www.facebook.com\/cheapsslweb","article_published_time":"2022-10-28T11:00:00+00:00","article_modified_time":"2025-12-10T10:53:17+00:00","og_image":[{"width":960,"height":621,"url":"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/10\/what-is-hsts-certificate.jpg","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_creator":"@cheapsslweb","twitter_site":"@cheapsslweb","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#article","isPartOf":{"@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate"},"author":{"name":"Janki Mehta","@id":"https:\/\/cheapsslweb.com\/resources\/#\/schema\/person\/c7d26eacacd9392c23be9d82e9af145e"},"headline":"What is HTTP Strict Transport Security? How to Enable HSTS?","datePublished":"2022-10-28T11:00:00+00:00","dateModified":"2025-12-10T10:53:17+00:00","mainEntityOfPage":{"@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate"},"wordCount":826,"commentCount":0,"publisher":{"@id":"https:\/\/cheapsslweb.com\/resources\/#organization"},"image":{"@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#primaryimage"},"thumbnailUrl":"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/10\/what-is-hsts-certificate.jpg","keywords":["HSTS Certificate","HSTS Encryption","HTTP Strict Transport Security (HSTS)"],"articleSection":["SSL and Encryption"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate","url":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate","name":"HTTP Strict Transport Security: How to Implement or Enable HSTS","isPartOf":{"@id":"https:\/\/cheapsslweb.com\/resources\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#primaryimage"},"image":{"@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#primaryimage"},"thumbnailUrl":"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/10\/what-is-hsts-certificate.jpg","datePublished":"2022-10-28T11:00:00+00:00","dateModified":"2025-12-10T10:53:17+00:00","description":"Know what is HSTS certificate, how to implement or enable HSTS and a step-by-step guide know on how HSTS stops SSL stripping attacks.","breadcrumb":{"@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#primaryimage","url":"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/10\/what-is-hsts-certificate.jpg","contentUrl":"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/10\/what-is-hsts-certificate.jpg","width":960,"height":621,"caption":"What is HSTS?"},{"@type":"BreadcrumbList","@id":"https:\/\/cheapsslweb.com\/resources\/what-is-hsts-certificate#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cheapsslweb.com\/resources\/"},{"@type":"ListItem","position":2,"name":"What is HTTP Strict Transport Security? How to Enable HSTS?"}]},{"@type":"WebSite","@id":"https:\/\/cheapsslweb.com\/resources\/#website","url":"https:\/\/cheapsslweb.com\/resources\/","name":"CheapSSLWeb.com","description":"SSL Errors and Installation Tutorials","publisher":{"@id":"https:\/\/cheapsslweb.com\/resources\/#organization"},"alternateName":"Cheap SSL Web","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cheapsslweb.com\/resources\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cheapsslweb.com\/resources\/#organization","name":"CheapSSLWeb","alternateName":"Cheap SSL Web","url":"https:\/\/cheapsslweb.com\/resources\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cheapsslweb.com\/resources\/#\/schema\/logo\/image\/","url":"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/03\/logo.png","contentUrl":"https:\/\/cheapsslweb.com\/resources\/wp-content\/uploads\/2022\/03\/logo.png","width":177,"height":60,"caption":"CheapSSLWeb"},"image":{"@id":"https:\/\/cheapsslweb.com\/resources\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/cheapsslweb","https:\/\/x.com\/cheapsslweb","https:\/\/www.linkedin.com\/company\/cheapsslweb\/","https:\/\/www.pinterest.com\/cheapsslweb\/","https:\/\/www.instagram.com\/cheapsslweb\/"]},{"@type":"Person","@id":"https:\/\/cheapsslweb.com\/resources\/#\/schema\/person\/c7d26eacacd9392c23be9d82e9af145e","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcheapsslweb.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fjanki-mehta-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcheapsslweb.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fjanki-mehta-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcheapsslweb.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fjanki-mehta-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a Cyber-Security Enthusiast having 7+ years of experience and knowledge about Encryption, Digital Certificates and Online Security, She helps online users to stay safe and protect their online presence. Explore SSL Errors, Installation Guide and Security Tutorials for Safe Browsing and Web Security Experience.","sameAs":["https:\/\/cheapsslweb.com\/","https:\/\/www.linkedin.com\/in\/pw-jankimehta\/"],"url":"https:\/\/cheapsslweb.com\/resources\/author\/janki-mehta"}]}},"_links":{"self":[{"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/posts\/390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/comments?post=390"}],"version-history":[{"count":18,"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/posts\/390\/revisions"}],"predecessor-version":[{"id":5052,"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/posts\/390\/revisions\/5052"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/media\/417"}],"wp:attachment":[{"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/media?parent=390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/categories?post=390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cheapsslweb.com\/resources\/wp-json\/wp\/v2\/tags?post=390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}