Plesk

How to enable/disable HTTP Strict-Transport-Security (HSTS) for a domain in Plesk?

Question

How to enable/disable HTTP Strict-Transport-Security (HSTS) for a domain in Plesk?

Answer

Note: A valid SSL certificate must be installed on the website, otherwise it'll not be accessible.

Note: The HSTS header won't be sent while the preferred domain is "www". There is an UserVoice created to improve this behavior

  1. Log into Plesk

  2. Install SSL It! extension in Extensions

  3. Navigate to Domains > example.com > Hosting Settings and make sure SSL/TLS support is enabled

  4. Navigate to Domains > example.com > SSL/TLS Certificates

  5. Click on the HSTS button:

    mceclip0.png

  6. Configure the HSTS options and click on Enable (or Disable) HSTS:

Exit mobile version