


How to enable HTTP Strict Transport Security (HSTS) in Apache?
Jul 13, 2025 am 01:12 AMEnable HSTS to force browsers to access websites via HTTPS, improving security. 1. To enable HTTPS in Apache, you must first configure HTTPS, and then add Strict-Transport-Security response header in the site configuration file or .htaccess; 2. To configure max-age (such as 31536000 seconds), includeSubDomains and preload parameters; 3. Make sure that the mod_headers module is enabled, otherwise run sudo a2enmod headers and restart Apache; 4. You can optionally submit to the HSTS Preload list, but it must meet the conditions such as HTTPS support for both the main site and the subdomain and the header is correct. It is recommended to use SSL Labs SSL Test to test configuration integrity before submitting.
Enable HSTS (HTTP Strict Transport Security) to force the browser to access your website only through HTTPS, improving security. It is not difficult to enable this function in Apache, but you need to have HTTPS configured.
Adding HSTS response header
HSTS is achieved by adding Strict-Transport-Security
to the server response header. In Apache, you can add this header by modifying the site configuration file or .htaccess
file.
Open your Apache site configuration file (such as /etc/apache2/sites-available/example.com.conf
), and then add the following code to the <virtualhost></virtualhost>
block:
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
This configuration means:
-
max-age
: Tells the browser how long it takes to access using HTTPS, in seconds. 31536000 means one year. -
includeSubDomains
: Applicable to all subdomains. -
preload
: means that you want the website to be added to the browser's HSTS preload list (the next steps will talk about whether to submit a preload).
If you are using .htaccess
, you can also add the same statement.
Make sure the mod_headers module is enabled
Header
directive mentioned above depends on Apache's mod_headers
module. If this module is not enabled, the settings will not take effect.
You can use the following command to check whether it is enabled:
sudo a2enmod headers
If you prompt "Module headers already enabled", it means there is no problem. Otherwise, remember to restart Apache after running:
sudo systemctl restart apache2
Submit HSTS Preload List (optional)
If you want your website to be hardcoded into the HSTS list in your browser to prevent HTTP still being used during the first visit, you can apply to join the HSTS Preload List .
But be aware of:
- Once the submission is successful, it cannot be easily revoked.
- Certain conditions must be met, such as both the main site and the
www
subdomain must support HTTPS, and the correct HSTS header must be returned.
Before submitting, it is recommended to test whether your configuration is correct. You can use tools such as SSL Labs SSL Test .
Basically that's it. As long as you ensure that HTTPS is normal, the header is set correctly, and the module is enabled, HSTS will work smoothly.
The above is the detailed content of How to enable HTTP Strict Transport Security (HSTS) in Apache?. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

The steps to deploy a Joomla website on PhpStudy include: 1) Configure PhpStudy, ensure that Apache and MySQL services run and check PHP version compatibility; 2) Download and decompress PhpStudy's website from the official Joomla website, and then complete the installation through the browser according to the installation wizard; 3) Make basic configurations, such as setting the website name and adding content.

PHP code can be executed in many ways: 1. Use the command line to directly enter the "php file name" to execute the script; 2. Put the file into the document root directory and access it through the browser through the web server; 3. Run it in the IDE and use the built-in debugging tool; 4. Use the online PHP sandbox or code execution platform for testing.

Reasons for system performance not recovered after uninstalling the Apache service may include resource occupancy by other services, error messages in log files, resource consumption by abnormal processes, network connection problems, and file system residues. First, check whether there are other services or processes before uninstalling with Apache; second, pay attention to the operating system's log files and find error messages that may occur during the uninstallation process; second, check the system's memory usage and CPU load, and find out abnormal processes; then, use the netstat or ss command to view the network connection status to ensure that no ports are occupied by other services; finally, clean up the remaining configuration files and log files after uninstallation to avoid occupying disk space.

Updating the Tomcat version in the Debian system generally includes the following process: Before performing the update operation, be sure to do a complete backup of the existing Tomcat environment. This covers the /opt/tomcat folder and its related configuration documents, such as server.xml, context.xml, and web.xml. The backup task can be completed through the following command: sudocp-r/opt/tomcat/opt/tomcat_backup Get the new version Tomcat Go to ApacheTomcat's official website to download the latest version. According to your Debian system

The command to start the Apache service on macOS is sudoapachectlstart, and the configuration file is located in /etc/apache2/. The main steps include: 1. Edit the httpd.conf file, modify the Listen port such as Listen8080; 2. Adjust the DocumentRoot path to the personal directory such as /Users/your_username/Sites, and update the corresponding permission settings; 3. Use the sudoapachectlgraceful command to restart Apache to ensure that the configuration takes effect; 4. Enable the mod_deflate module to compress data to improve page loading speed.

The reasons for file deletion failure during Apache uninstall include file permission issues, locking files, and running processes. Solutions include: 1. Stop the Apache service: sudosystemctlstoppapache2; 2. Manually delete the Apache directory: sudorm-rf/etc/apache2/usr/sbin/apache2; 3. Use lsof to find and terminate the process of locking the file: sudolsof|grepapache2, and then sudokill-9; 4. Try to delete the file again.

Configuring Apache to connect to MySQL database requires the following steps: 1. Make sure that Apache and MySQL are installed; 2. Configuring Apache to support PHP, by adding LoadModule and AddHandler instructions in httpd.conf or apache2.conf; 3. Configuring PHP to connect to MySQL, enable mysqli extension in php.ini; 4. Create and test the connected PHP file. Through these steps, the connection between Apache and MySQL can be successfully implemented.

There are many methods and tools for monitoring Hadoop clusters on Debian systems. The following are some commonly used monitoring tools and their usage methods: Hadoop's own monitoring tool HadoopAdminUI: Access the HadoopAdminUI interface through a browser to intuitively understand the cluster status and resource utilization. HadoopResourceManager: Access the ResourceManager WebUI (usually http://ResourceManager-IP:8088) to monitor cluster resource usage and job status. Hadoop
