Skip to content
Jorge Vallecillo edited this page Aug 2, 2020 · 2 revisions

TWA-0202

Message

"Strict-Transport-Security max-age is less than 6 months"

Explanation

Strict-Transport-Security headers are cached by the user browser. Having a STS header for a short duration means that more users are susceptible to downgrade attacks. If a user visits your website once over HTTP, their browser should receive the redirect, and cache the STS header for at least 6 months.

Remediation

Set the Strict-Transport-Security header's max-age parameter to atleast 6 months (15778800 seconds).

Clone this wiki locally