I have enabled HSTS security setting from my cloudflare account, but still my website has failed under security audit, because of this reason. HSTS Missing From HTTPS Server (RFC 6797). Please help me in this

Major issue is this: HSTS Missing From HTTPS Server (RFC 6797). Help me to sort out this issue

Is the hostname you are testing configured as :orange:?

Can you share the hostname, and a screenshot of the HSTS settings for this domain?

Hostname is herbalcart.com!

Is the hostname you are testing configured as :orange:?
I have just configured via IP address, and its working as well!

See the below settings that I have done for HSTS

HTTP Strict Transport Security (HSTS)

Enforce web security policy for your website.

Status: On
Max-Age: 12 months
Include subdomains: On
Preload: On

You are using Shopify, so the HSTS header that is seen is theirs, with a 90 day max-age.

What exactly does your report say?

Yes, using shopify. see the below screenshot

Screenshot 2023-02-12 at 4.49.40 PM|690x300

Thanks in advance!

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.