HSTS and TLS Configuration: The Decisions That Matter
Configuring HTTPS properly, including protocol versions, cipher choices and strict transport security.
The key figures
- HSTS
- tells browsers to use HTTPS for a domain
- Preload
- browsers can ship HSTS settings, which is hard to undo
- Protocol versions
- older TLS versions are deprecated
- Mixed content
- insecure subresources undermine HTTPS
Why this is worth getting right
A certificate alone does not make a site secure, and weak configuration leaves known attacks open.
Do this, not that
Do
- Redirect all HTTP traffic to HTTPS
- Enable HSTS once HTTPS is stable
- Disable deprecated protocol versions
- Fix mixed content warnings
- Test configuration with a scanning tool
Don’t
- HSTS preload before you are certain
- Deprecated TLS versions left enabled
- Mixed content on secure pages
- Configuration never reviewed after setup
When to bring in help
Our advice Bring in help when hardening sites that handle payments or logins.
Where this comes from
- MDN Web Docs — Strict-Transport-Security
- OWASP — Transport Layer Security Cheat Sheet
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.