How-to Enable HTTP Strict Transport Security (HSTS)

Опубликовано: 21 Апрель 2026
на канале: FICHEBAIT
4,361
21

Welcome to our step-by-step guide on enabling HTTP Strict Transport Security (HSTS) in IIS 10.0! In this video, we'll walk you through the process to ensure your website is accessible only via secure HTTPS connections, enhancing your site's security against man-in-the-middle attacks.

Steps Covered:
1. Open IIS Manager: Launch Internet Information Services (IIS) Manager on your server.
2. Select Your Site: Choose the site you want to configure HSTS for.
3. Access HSTS Settings: In the Actions bar, under the Configure section, click on HSTS.
4. Enable HSTS: In the Edit Website HSTS dialog, select the Enable option.
5. Set Max-Age: Specify the duration (in seconds) for which the browser should remember to access the site via HTTPS. The default value is 31536000 seconds (1 year).
6. Redirect HTTP to HTTPS: Ensure the Redirect Http to Https option is selected.
7. Include Subdomains (Optional): Optionally, select the IncludeSubDomains option to apply the rule to all subdomains of your site.

Additional Information:
For Laserfiche Forms, you can also set the HSTS header in the Forms Configuration site's Security section.
If HSTS is enabled in both IIS and FormsConfig, the IIS configuration will take precedence.
Don't forget to like, comment, and subscribe for more tutorials on web security and server management!

Links:
Laserfiche Support Article: https://support.laserfiche.com/kb/101...

#laserfiche #iis #hsts #windowsserver

00:00 Introduction
00:12 Goal: Enable HSTS in IIS

👍 Remember to hit that Subscribe button and turn on notifications to stay updated with our Laserfiche content. If you have any questions or need further assistance, drop them in the comments below!

#hsts #windowssecurity #iis #keepfiching #windowsserver