Skip to content

Secure connection upgrade not enforced. #6

@aaronhans

Description

@aaronhans

Issue

security: HTTP Strict Transport Security (HSTS)

Error

Secure connection upgrade not enforced.

Why is this a problem

HSTS is a security feature that ensures a website is only accessible over HTTPS. It helps to prevent man-in-the-middle attacks, such as protocol downgrade attacks, by enforcing that browsers always communicate with the server over a secure connection. Without HSTS, an attacker could intercept traffic on a non-secure connection and compromise user data.

Prevalence

This is a sitewide issue

Description

Site upgrades to a secure connection.

Documentation

ScanGov HTTP Strict Transport Security (HSTS) docs

21st Century Integrated Digital Experience Act

CISA Website Security

CISA Cybersecurity Performance Goals

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions