Skip to main content
DigiCert, Sectigo and GeoTrust SSL certificates
+90 850 259 76 06 WhatsApp Support Become a Reseller
SSL Certificates
Brands
Code Signing LEI Code
Tools
Support Contact WhatsApp Cart
Language
Currency
Get an SSL Certificate
SSL Security

HSTS Error and Strict-Transport-Security Configuration Guide

HSTS (HTTP Strict Transport Security) errors, misconfiguration and expiration issues. HSTS preload, max-age settings and solutions to common errors.

9 min read

What is HSTS?

HSTS (HTTP Strict Transport Security) is the security mechanism by which a website instructs the browser to "only connect to this site via HTTPS". On an HSTS-enabled site, the browser automatically upgrades HTTP connection attempts to HTTPS — the HTTP request does not even go to the server.

How Does HSTS Work?

  1. The browser visits your site for the first time with HTTPS
  2. Server sends Strict-Transport-Security header
  3. The browser saves this information for max-age
  4. HTTP links are automatically upgraded to HTTPS on subsequent visits
# Basic HSTS header
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

Common HSTS Errors

Error 1: ERR_SSL_PROTOCOL_ERROR (Due to HSTS)

If the SSL certificate expires or a problem occurs while HSTS is active, the browser will refuse to open the site with HTTP as well. Unlike a normal SSL error, the user will not see the "Continue anyway" option.

Solution

  • Renew SSL certificate immediately — Without HSTS, leaving the site completely inaccessible
  • In Chrome, you can delete the domain's HSTS record from chrome://net-internals/#hsts (in your browser only)

Error 2: No SSL on Subdomains but includeSubDomains is Active

The

includeSubDomains directive enforces HTTPS on all subdomains. If a subdomain does not have SSL, that subdomain will be inaccessible.

Solution

  • Install SSL certificate on all subdomains (at once with Wildcard SSL)
  • Or remove the includeSubDomains directive

Error 3: Sending HSTS from HTTP Page

The HSTS header is valid only in HTTPS responses. HSTS sent in the HTTP response is ignored by browsers.

Correct Configuration

# Nginx
server {
    listen 80;
    server_name example.com;
    return 301 https://$host$request_uri;  # Redirect to HTTPS first
}

server {
    listen 443 ssl;
    server_name example.com;
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;  #HSTS is here
}

Error 4: max-age Too Short or Zero

max-age=0 Disables HSTS. Very short periods (a few hours) weaken security.

Recommended Settings

Stagemax-ageDescription
Test300 (5 minutes)Safe test at first installation
Transition604800 (1 week)Increase if OK
Production31536000 (1 year)Standard production value
Preload31536000+ (1 year+)Minimum for HSTS preload list

What is HSTS Preload?

HSTS Preload adds your domain to Chrome's (and other browsers') built-in HSTS list. In this way, no HTTP connection attempt is made even on the first visit.

Preload Requirements

  • Valid SSL certificate
  • HTTP → HTTPS redirect
  • max-age at least 31536000 (1 year)
  • includeSubDomains directive
  • preload directive

Application: You can send your domain from hstspreload.org.

⚠️ Warning: It may take months to be removed from the HSTS preload list. Do not apply unless you are sure.

HSTS Disable

To disable HSTS in emergency situations:

Send
# max-age=0
add_header Strict-Transport-Security "max-age=0" always;
# Browsers will delete the HSTS record on their next visit to the site over HTTPS

Server Based HSTS Configuration

# Nginx
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;

# Apache (.htaccess or VirtualHost)
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"

# IIS (web.config)
<customHeaders>
    <add name="Strict-Transport-Security" value="max-age=31536000; includeSubDomains; preload" />
</customHeaders>

Conclusion

HSTS is a powerful mechanism that significantly increases the security of your website. However, if not configured correctly, it can cause access problems. Before HSTS activation, make sure all subdomains have an SSL certificate, gradually increase the max-age value, and thoroughly test your configuration before adding it to the preload list.

Share this post
Ali Yiğit
Yazar

Ali Yiğit

Recommended SSL Certificates

All Products
EV Certum

Certum Premium EV Multi-Domain SSL

Protect multiple domains at EV level with Certum Premium EV Multi-Domain SSL. Company name visible i

$419.00 /yr
Details
EV Certum

Certum Premium EV SSL

Get the most comprehensive identity validation with Certum Premium EV SSL. Extended validation, comp

$654.58 /yr
Details
OV Certum

Certum Trusted Multi-Domain SSL

Protect multiple domains at OV level with Certum Trusted Multi-Domain SSL. Company name visible, 4,

$50.00 /yr
Details