HTTP Strict Transport Security
RFC 6797, “HTTP Strict Transport Security”, is a Proposed Standard document published in November 2012 by J. Hodges, C. Jackson, A. Barth. The canonical text is published by the RFC Editor.
Abstract
This specification defines a mechanism enabling web sites to declare themselves accessible only via secure connections and/or for users to be able to direct their user agent(s) to interact with given sites only over secure connections. This overall policy is referred to as HTTP Strict Transport Security (HSTS). The policy is declared by web sites via the Strict-Transport-Security HTTP response header field and/or by other means, such as user agent configuration, for example. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6797 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6796 A User Agent Profile Data Set for Media Policy
- RFC 6798 RTP Control Protocol Extended Report Block for Packet Delay Variation Metric Reporting
- RFC 6795 A Session Initiation Protocol Event Package for Session- Specific Policies
- RFC 6794 A Framework for Session Initiation Protocol Session Policies
- RFC 6793 BGP Support for Four-Octet Autonomous System Number Space
- RFC 6801 Pseudo Content Delivery Protocol for Protecting Multiple Source Flows in the Forward Error Correction Framework
- RFC 6792 Guidelines for Use of the RTP Monitoring Framework
- RFC 6802 Ericsson Two-Way Active Measurement Protocol Value-Added Octets