HTTP 厳密な転送セキュリティ (HSTS) のサポートを構成する
maxageパラメータを使用して、そのクライアントに対して HSTS がその期間有効であることを指定します。デフォルトでは、HSTS ヘッダーはルートドメインにのみ適用されます。サブドメインを含める必要があるかどうかを指定できます。たとえば、IncludeSubdomainsパラメータを YES に設定すると、www.abc.example.com や www.xyx.example.com などの www.example.com のサブドメインに HTTPS を使用してのみアクセスできるように指定できます。サブドメインは HTTPS をサポートしている必要があります。ただし、それぞれの HSTS を有効にする必要はありません。
maxageパラメータを 31536000 に設定すると、ブラウザは HTTPS のみを使用してドメインにアクセスすることを 1 年間記憶します。
CLI を使用して HSTS を構成する
add ssl vserver <vServerName> -maxage <positive_integer> -IncludeSubdomains ( YES | NO)
set ssl vserver <vServerName> -HSTS ( ENABLED | DISABLED )
add ssl profile <name> -maxage <positive_integer> -IncludeSubdomains ( YES | NO )
set ssl profile <name> -HSTS ( ENABLED | DISABLED )
Arguments
HSTS
State of HTTP Strict Transport Security (HSTS) on an SSL virtual server or SSL profile. Using HSTS, a server can enforce the use of an HTTPS connection for all communication with a client.
Possible values: ENABLED, DISABLED
Default: DISABLED
maxage
Set the maximum time, in seconds, in the strict transport security (STS) header during which the client must send only HTTPS requests to the server.
Default: 0
Minimum: 0
Maximum: 4294967294
IncludeSubdomains
Enable HSTS for subdomains. If set to Yes, a client must send only HTTPS requests for subdomains.
Possible values: YES, NO
Default: NO
add ssl vserver VS-SSL –maxage 157680000 –IncludeSubdomain YES
set ssl vserver VS-SSL –HSTS ENABLEDadd sslProfile hstsprofile –maxage 157680000 –IncludeSubdomain YES
set sslProfile hstsprofile –HSTS ENABLED
GUI を使用して HSTS を構成する
HSTS プリロードのサポート
preloadパラメーターを YES に設定する必要があります。アプライアンスは、クライアントへの HTTP 応答ヘッダーにプリロードを含めます。この機能は、CLI と GUI の両方を使用して設定できます。HSTS プリロードの詳細については、「<https://hstspreload.org/>」を参照してください。
Strict-Transport-Security: max-age=63072000; includeSubDomains; preloadStrict-Transport-Security: max-age=63072000; preload
CLI を使用して HSTS プリロードを構成する
add ssl vserver <vServerName> -maxage <positive_integer> -preload ( YES | NO )
set ssl vserver <vServerName> -HSTS ( ENABLED | DISABLED )
add ssl profile <name> -maxage <positive_integer> -IncludeSubdomains ( YES | NO ) -preload ( YES | NO )
set ssl profile <name> -HSTS ( ENABLED | DISABLED )
GUI を使用して HSTS プリロードを構成する
-
Traffic Management > Load Balancing > Virtual Serversに移動します。
-
HSTS****とプリロードを選択します。

使用例
<http://www.exemple.com>に変換します。ブラウザは exemple.com という名前を検出し、DNS サーバーと通信してホストサーバーの IP アドレスを取得します。 ブラウザはポート 80 を使用して IP アドレスにアクセスします。銀行のウェブサイトはリクエストを<https://www.exemple.com>にリダイレクトします。SSL ハンドシェイクが実行され、SSL 接続が確立されます。 URL の南京錠が緑色に変わり、ロックされていると表示されます。 これで、ユーザー 1 は認証情報を入力して取引を行うことができます。
問題シナリオ
<https://www.example.com> (スペルが少し変わっていることに注意してください)。ユーザー 1 はこの不一致に気付かず (exemple.com ではなく example.com)、認証情報を入力する可能性があります。
解決策
add ssl profile sample-profile -maxage 63072000 -IncludeSubdomains YES -preload YES
set ssl profile sample-profile -HSTS ENABLED


