Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC6797
Discuss this RFC: Send questions or comments to the mailing listwebsec@ietf.org
Other actions:View Errata | Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 6797
This specification defines a mechanism enabling web sites to declarethemselves accessible only via secure connections and/or for users tobe able to direct their user agent(s) to interact with given sitesonly over secure connections. This overall policy is referred to asHTTP Strict Transport Security (HSTS). The policy is declared by websites via the Strict-Transport-Security HTTP response header fieldand/or by other means, such as user agent configuration, for example.[STANDARDS-TRACK]
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.