Strict-Transport-Security "max-age=31536000; includeSubDomains"
Strict-Transport-Secutiry
を追加するだけ
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains"
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';
% curl --head 53ningen.com HTTP/1.1 301 Moved Permanently Server: nginx Date: Thu, 04 Jan 2018 14:05:38 GMT Content-Type: text/html Content-Length: 178 Connection: keep-alive Location: https://53ningen.com/ Strict-Transport-Security: max-age=2592000; preload
https://hstspreload.org/ で登録する
307 でリダイレクトがかかる模様
https://www.ssllabs.com/ssltest/analyze.html?d=53ningen.com で見れば HSTS が有効になっていることがわかる
Strict Transport Security (HSTS) Yes max-age=31536000; includeSubDomains; preload HSTS Preloading Not in: Chrome Edge Firefox IE
ウェブ界隈でエンジニアとして労働活動に励んでいる @gomi_ningen 個人のブログです