Secure Foray ADAMSĀ® Web Applications with HSTS
HTTP Strict-Transport-Security (aka HSTS) can be enabled for IIS web sites. This will causes the clientās browser, after an initial connection, to only use HTTPS.
IIS Manager > <Server> > Sites > Default Web Site
HSTSā¦ (under Configure on the far right)
Enable
Max-Age - 63072000 (2 year)
Redirect Http to Https
OK
Preload is optional and requires that the site be external and must be submitted to Google for inclusion in the HSTS preload list.
Ā
Ā© 2023 Foray, LLC - All Rights Reserved