Skip to main content

May 28, 2026

HTTP Strict Transport Security

The HTTP Strict Transport Security (HSTS) feature is a security policy mechanism that helps to protect against man-in-the-middle attacks by telling web browsers that they should use only HTTPS to connect.

The header is added to all HTTP responses on port 443, specifying a lifetime of one year. Optional properties can be set by adding multi-value property hstsFlags to the locked.properties file. The following values can be set.

PropertyValue
includeSubDomainsApplies to all subdomains of this site.
preloadHint to include this site in HSTS preload lists.

Example:

hstsFlags.1=includeSubDomains
hstsFlags.2=preload

Note: These properties are not set by default because they can affect URLs outside of Horizon 8 too. Do not set unless you understand the implications.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…