Canonical HTTPS Block

A Canonical Host, HTTPS and HSTS Block

Canonical Host and HTTPS needs one hop, but the HSTS preload list (https://hstspreload.org/ 26,500 ) wants HTTP sent to HTTPS on the same host first, so this version takes two:

A canonical host with HSTS, ready for the preload listApache config
# Needs: mod_rewrite, mod_headers; AllowOverride FileInfo; Options FollowSymLinks
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteCond %{HTTP_HOST} ^((www\.)?example\.com)$ [NC]
RewriteRule ^ https://%1%{REQUEST_URI} [R=301,L]
RewriteCond %{HTTP_HOST} !^example\.com$
RewriteRule ^ https://example.com%{REQUEST_URI} [R=301,L]
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" \
  "expr=%{HTTPS} == 'on'"

Lines 3 to 5 upgrade the two known names in place, never a forged Host; lines 6 and 7 send other aliases, and www over HTTPS, to the canonical host; lines 8 and 9 add HSTS over HTTPS:

Output of 79
http://www.example.com/?x=1    301 https://www.example.com/?x=1
https://www.example.com/?x=1   301 https://example.com/?x=1     HSTS
https://example.com/?x=1       200                              HSTS
http://old.example.net/        301 https://example.com/

Preloading needs at least a year's max-age and is slow to undo; start with max-age=300.