Strict-Transport-Security

Prev Next

Municipal Websites Central supports the addition of HSTS (HTTP Strict Transport Security) headers.

Considerations

  • Once HSTS (HTTP Strict Transport Security) is on, it cannot be easily turned off. This is due to the max-age directive of HSTS. Turning it off will not have any effect until the maximum age is reached.

  • It is generally recommended that the maximum age be 1 year or more.

  • Once a machine visits a domain with HSTS headers present, that machine will only be able to access that domain's site over HTTPS.

  • If the SSL on your site expires, the site will be inaccessible until a new SSL is installed. There is no way to bypass the SSL warnings when HSTS is on.


Domains and Subdomains

In Municipal Websites Central, HSTS (HTTP Strict Transport Security) is enabled for the entire website, not for an individual domain assigned to that website. If multiple domains are assigned to the same site, each domain will return the HSTS header when accessed over HTTPS.

For example, if example.gov and example.org are both assigned to the same Municipal Websites Central site, enabling HSTS affects both domains. Each domain must have and maintain a valid SSL certificate and working HTTPS configuration. After a visitor’s browser receives the HSTS policy for a domain, that browser will require HTTPS for future visits. If HTTPS or the certificate for that domain stops working, the domain may become inaccessible to that visitor.

If includeSubDomains is selected, the risk is broader. The browser will also require HTTPS for every current and future subdomain of each affected domain. Those subdomains may host services outside CivicPlus, such as email, payments, legacy applications, or third-party systems. Any affected subdomain without working HTTPS and a valid certificate may become inaccessible.

Before requesting HSTS, confirm that:

  • Every domain assigned to the Municipal Websites Central site supports HTTPS.

  • Every domain has a valid certificate that will be maintained.

  • If includeSubDomains is requested, every current and future subdomain, including services not hosted by CivicPlus, supports HTTPS.


Default Deployment

When we enable HSTS (HTTP Strict Transport Security), our default deployment is to:

  • Not include subdomains. By default, CivicPlus does not enable includeSubDomains. HSTS is configured for the entire Municipal Websites Central site and therefore affects all domains assigned to that site. Enabling includeSubDomains would additionally require HTTPS for the subdomains of those domains, including subdomains that may not be hosted by CivicPlus.

  • Set max-age to 1 year.

  • Not enable preload.

If you are ready to have HSTS enabled, please contact our Support team. Acknowledge in the ticket that you understand the risks outlined in this article.