Learn about the health checks that check for cookie hijacking and protocol downgrade attacks protection.
Checks if your site, when running with HTTPS, contains the Strict-Transport-Security Header (HSTS).
This health check can be fixed by adding the
Strict-Transport-Securityheader to responses. The header tells browsers that future requests should be made over HTTPS only.
Enabling HSTS on a domain will cause browsers to only use HTTPS (not HTTP) to communicate with your site. Only enable HSTS on domains that can, and should, use HTTPS exclusively.
ASP.NET Core implements HSTS with the
You can add
public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
This example only enables HSTS if the app is not running in development mode.
UseHstsisn't recommended in development because the HSTS settings are highly cacheable by browsers.
Full details of
UseHsts, and additional configuration, can be found in the ASP.NET Core documentation.