Ruggerfly1
Feb 06, 2017Nimbostratus
HSTS Irule and Validating Results
Good Morning, I have IRULES on the HTTP and HTTPS virtual servers to enforce HSTS, how can I test it's being inserted correctly? I used SSL Labs but the Server Scan didn't exactly give me what I was expecting:
HSTS not in Chrome, Firefox, IE.
My config is: V11.5.3 HF2
**HTTP VIP IRULE when HTTP_REQUEST { HTTP::respond 301 Location "https://[HTTP::host][HTTP::uri]" }
**HTTPS VIP IRULE when RULE_INIT { set static::max_age 15552000 } when HTTP_RESPONSE { HSTS HTTP::header insert Strict-Transport-Security "max-age=$static::max_age; includeSubDomains" }
Many thanks,