• Resolved Infinitee

    (@infinitee)


    Added to .htaccess…

    # SSL header enhancements
    Header always set Strict-Transport-Security: "max-age=31536000" env=HTTPS
    Header always set Content-Security-Policy "upgrade-insecure-requests"
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-XSS-Protection "1; mode=block"
    Header always set Referrer-Policy: "no-referrer-when-downgrade"
    Header always set Expect-CT "max-age=7776000, enforce"
    Header always set X-Frame-Options: "SAMEORIGIN"
    Header always set Permissions-Policy: ""

    Settings SSL says:
    The following recommended security headers are not detected:
    HTTP Strict Transport Security

    It appears to have resolved it’s self.

    • This topic was modified 2 years, 8 months ago by Infinitee.

    The page I need help with: [log in to see the link]

  • The topic ‘Strict-Transport-Security set but not detected’ is closed to new replies.