RFC 6797: HTTP Strict Transport Security (HSTS)
In plain English — editorial summary, not part of the RFC
This specification defines a mechanism enabling web sites to declare themselves accessible only via secure connections and/or for users to be able to direct their user agent(s) to interact with given sites only over secure connections. This overall policy is referred to as HTTP Strict Transport Security (HSTS). The policy is declared by web sites via the Strict-Transport-Security HTTP response header field and/or by other means, such as user agent configuration, for example. [STANDARDS-TRACK]
Document record
- Document ID
- RFC6797
- Published
- November 2012
- Authors
- J. Hodges; C. Jackson; A. Barth
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- app
- Pages
- 46
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6813The Network Endpoint Assessment (NEA) Asokan Attack AnalysisCurrent
December 2012
- RFC 7029Extensible Authentication Protocol (EAP) Mutual Cryptographic BindingCurrent
October 2013
- RFC 7457Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)Current
February 2015
- RFC 7525Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)Obsoleted
May 2015
- RFC 7568Deprecating Secure Sockets Layer Version 3.0Updated
June 2015
- RFC 7590Use of Transport Layer Security (TLS) in the Extensible Messaging and Presence Protocol (XMPP)Current
June 2015
- RFC 4513Lightweight Directory Access Protocol (LDAP): Authentication Methods and Security MechanismsUpdated
June 2006
- RFC 4511Lightweight Directory Access Protocol (LDAP): The ProtocolCurrent
June 2006
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?