An Off-Site Way to Speed Up Site Access: Submit to the HSTS Preload List
This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文
What Is the HSTS Preload List?
HTTP Strict Transport Security, or HSTS, is a web security policy mechanism that helps protect websites against man-in-the-middle attacks, such as protocol downgrade attacks and cookie hijacking. It allows web servers to declare that web browsers (or other compliant user agents) should automatically interact with them only over HTTPS connections secured with Transport Layer Security (TLS / SSL), rather than insecure HTTP.
The server communicates its HSTS policy to the user agent through an HTTPS response header named “ Strict-Transport-Security ”. The HSTS policy specifies how long the user agent must access the server only over secure connections. Websites that use HSTS typically do not accept plaintext HTTP: they either reject HTTP connections or redirect them to HTTPS.
Why Does HSTS Preloading Make Browsing Faster?
In simple terms, HSTS forces browsers to connect only over HTTPS. The HSTS preload list was introduced by Chrome and is now supported by other major browsers, including Chrome, Firefox, Opera, Safari, IE 11, and Edge. When browsers release a new version, they include a hardcoded list of domains that support HSTS. When a user visits one of these domains (note: this includes all subdomains), the browser automatically connects over HTTPS. This reduces handshake time with the server, making access both safer and faster.
How to Add a Domain to the HSTS Preload List
1. First, install an SSL certificate for the domain and enable HTTPS across the entire site (no page may load resources over HTTP).
2. HTTP connections must redirect to HTTS using a 301 or 302 redirect. Here is an Nginx example:
server
{
listen 80;
server_name abc.com www.abc.com;
index index.php index.html index.htm default.php default.htm default.html;
root /wwwroot/abc;
if ($server_port !~ 443){
rewrite ^(/.*)$ https://$host$1 permanent;
}
}
3. Serve an HSTS header for HTTPS requests on the base domain (not a subdomain):
- max-age must be at least 31536000 seconds (1 year).
- The includeSubDomains directive must be specified.
- The preload directive must be specified.
Here is an Nginx example that adds the “Strict-Transport-Security” header:
server
{
listen 443 ssl http2;
server_name abc.com www.abc.com;
index index.php index.html index.htm default.php default.htm default.html;
root /wwwroot/abc;
#HTTP_TO_HTTPS_END
ssl_certificate /cert/fullchain.pem;
ssl_certificate_key /cert/privkey.pem;
ssl_protocols TLSv1.1 TLSv1.2 TLSv1.3;
ssl_ciphers EECDH+CHACHA20:EECDH+CHACHA20-draft:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
add_header Strict-Transport-Security "max-age=31536000;includeSubdomains; preload";
#……N lines omitted here
error_log /wwwlogs/error.log;
}
Submit your domain at https://hstspreload.org/. If the submission succeeds, you will see the following:
If you see any other error messages, check that you have followed the steps above correctly.
Generally, if the status is pending submission, the domain will be added to the browser's HSTS preload list when the next browser update is released, in about 7-30 days.
Last updated 2025-01-14
Comments 0