Definition · Security Headers

What is HTTP to HTTPS Redirect?

Users type bare hostnames, old links point at http://, and clients default to port 80 when nothing says otherwise. A redirect handles that: the server listens on port 80 and answers with 301 Moved Permanently (or 308) to the same resource over HTTPS. It is the baseline for any site that intends to be encrypted, and it is easy to get subtly wrong.

The gap a redirect cannot close

The first request still leaves the client in plaintext. An attacker on the path can intercept it before the redirect arrives and simply keep the conversation on HTTP, proxying content from the real site while stripping the upgrade — an SSL stripping attack. The user sees a working page with no padlock, and most will not notice.

HSTS closes that gap. Once a browser has seen a Strict-Transport-Security header from a host, it rewrites subsequent http:// requests to https:// internally, before any traffic is sent. The redirect is what allows the header to be delivered in the first place; the header is what makes the redirect unnecessary from then on. For the very first visit, HSTS preloading removes the gap entirely by shipping the policy with the browser.

Getting the details right

  • Preserve path and query string. Redirect to the same resource, not to the homepage.
  • Redirect to the same host first. http://example.com should go to https://example.com before any redirect to www, so the HSTS header is delivered for the host that was requested.
  • Do not send HSTS over HTTP. Browsers ignore it on insecure responses; set it on the HTTPS response.
  • Cover every hostname. Redirects are per-server-block, so subdomains, legacy vanity domains and API hosts each need their own.
  • Mind the chains. Three or four hops to reach the canonical URL is slow and makes the behaviour hard to reason about.
  • Check the redirect target actually works. A redirect to an HTTPS endpoint with an expired or self-signed certificate turns a working page into a warning screen.

Having redirected, audit the pages themselves for mixed content, since a page served over HTTPS that pulls subresources over HTTP has reintroduced part of the problem.

See HSTS, mixed content, TLS, POODLE for the downgrade family of attacks, and security headers.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.