Skip to content
Web Design & Development

HSTS and TLS Configuration: The Decisions That Matter

Configuring HTTPS properly, including protocol versions, cipher choices and strict transport security.

Marcus Adeyemi Technical Director 2 min read 26 views
HSTS and TLS Configuration: The Decisions That Matter

The key figures

HSTS
tells browsers to use HTTPS for a domain
Preload
browsers can ship HSTS settings, which is hard to undo
Protocol versions
older TLS versions are deprecated
Mixed content
insecure subresources undermine HTTPS

Why this is worth getting right

A certificate alone does not make a site secure, and weak configuration leaves known attacks open.

Do this, not that

Do

  • Redirect all HTTP traffic to HTTPS
  • Enable HSTS once HTTPS is stable
  • Disable deprecated protocol versions
  • Fix mixed content warnings
  • Test configuration with a scanning tool

Don’t

  • HSTS preload before you are certain
  • Deprecated TLS versions left enabled
  • Mixed content on secure pages
  • Configuration never reviewed after setup

When to bring in help

Our advice Bring in help when hardening sites that handle payments or logins.

Where this comes from

  • MDN Web Docs — Strict-Transport-Security
  • OWASP — Transport Layer Security Cheat Sheet

The figures and practices above come from the sources listed.

Working on something like this?

We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.

Where to go next

Spotted something wrong? Report an error on this page. We correct on the page and say what changed.

All services

The work behind this article, and what it costs.

Marcus Adeyemi

Builds and maintains the web work. Writes about front-end architecture, performance, accessibility and the unglamorous parts of keeping a site alive.

Keep reading

More in Web Design & Development