<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq</link><pubDate>Wed, 13 Jul 2022 16:31:48 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Elly Meng</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Current Revision posted to Appian Knowledge Base by Elly Meng on 7/13/2022 4:31:48 PM&lt;br /&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#Does%20Appian%20support%20HSTS%20(HTTP%20Strict%20Transport%20Security)%20headers?"&gt;Does Appian support HSTS (HTTP Strict Transport Security) headers?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#How%20can%20I%20enable%20the%20HSTS%20header%20on%20Appian%20Cloud%20sites?"&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#How%20can%20I%20enable%20HSTS%20on%20Appian%20self-managed%20environments?"&gt;How can I enable HSTS on Appian self-managed environments?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#How%20do%20I%20confirm%20if%20my%20Appian%20site%20is%20enabled%20with%20the%20HSTS%20header?"&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#support-HSTS-Preloading"&gt;Does Appian support HSTS Preloading?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#HSTS-Preloading-default-domain"&gt;Is HSTS Preloading enabled on Appian Cloud instances configured with the default appiancloud.com domain?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#HSTS-Preloading-custom-domains"&gt;Is HSTS Preloading enabled on Appian Cloud customer instances with custom domains?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#HSTS-Preloading-Community-Edition"&gt;Is HSTS Preloading enabled on Appian Community Edition instances?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#enable-HSTS-Preloading-self-managed"&gt;How can I enable HSTS Preloading on self-managed environments?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="Does Appian support HSTS (HTTP Strict Transport Security) headers?"&gt;&lt;/a&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="How can I enable the HSTS header on Appian Cloud sites?"&gt;&lt;/a&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="How can I enable HSTS on Appian self-managed environments?"&gt;&lt;/a&gt;How can I enable HSTS on Appian self-managed environments?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="How do I confirm if my Appian site is enabled with the HSTS header?"&gt;&lt;/a&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/640x480/__key/communityserver-wikis-components-files/00-00-00-00-11/3771.updated_2D00_hsts_2D00_screenshot.png" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/0003.hsts.PNG"&gt;&lt;/a&gt;&lt;b&gt;&lt;a id="support-HSTS-Preloading"&gt;&lt;/a&gt;Does Appian support HSTS Preloading?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Yes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;a id="HSTS-Preloading-default-domain"&gt;&lt;/a&gt;Is HSTS Preloading enabled on Appian Cloud instances configured with the default appiancloud.com domain?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Yes, HSTS Preloading is implemented for Appian Cloud sites configured with the default domain. The appiancloud.com domain is included in the &lt;a href="https://hstspreload.org/?domain=appiancloud.com"&gt;preload list maintained by Google&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;a id="HSTS-Preloading-custom-domains"&gt;&lt;/a&gt;Is HSTS Preloading enabled on Appian Cloud customer instances with custom domains?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Appian Cloud sets the preload directive in the Strict-Transport-Security header for all customer instances including those configured with custom domains. Refer to the Mozilla Developer Network for more details around &lt;a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security#preloading_strict_transport_security"&gt;Preloading&amp;nbsp; Strict Transport Security&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If customers need their domain preloaded in the list maintained by Google, customers can submit their own custom domain to the &lt;a href="https://hstspreload.org/"&gt;HSTS Preload list&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;a id="HSTS-Preloading-Community-Edition"&gt;&lt;/a&gt;Is HSTS Preloading enabled on Appian Community Edition instances?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;At this time, Appian Community Edition (ACE) sites do not have the HSTS preload directive enabled.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;a id="enable-HSTS-Preloading-self-managed"&gt;&lt;/a&gt;How can I enable HSTS Preloading on self-managed environments?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This needs to be enabled on the web server that is being used with Appian using the preload directive in the Strict-Transport-Security header. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2022&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/14</link><pubDate>Wed, 12 Dec 2018 15:09:08 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 14 posted to Appian Knowledge Base by Jordan Horwat on 12/12/2018 3:09:08 PM&lt;br /&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="#Does%20Appian%20support%20HSTS%20(HTTP%20Strict%20Transport%20Security)%20headers?"&gt;Does Appian support HSTS (HTTP Strict Transport Security) headers?&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="#How%20can%20I%20enable%20the%20HSTS%20header%20on%20Appian%20Cloud%20sites?"&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="#How%20can%20I%20enable%20HSTS%20on%20Appian%20self-managed%20environments?"&gt;How can I enable HSTS on Appian self-managed environments?&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="#How%20do%20I%20confirm%20if%20my%20Appian%20site%20is%20enabled%20with%20the%20HSTS%20header?"&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;strong&gt;&lt;a id="Does Appian support HSTS (HTTP Strict Transport Security) headers?"&gt;&lt;/a&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Yes.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;a id="How can I enable the HSTS header on Appian Cloud sites?"&gt;&lt;/a&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;a id="How can I enable HSTS on Appian self-managed environments?"&gt;&lt;/a&gt;How can I enable HSTS on Appian self-managed environments?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;a id="How do I confirm if my Appian site is enabled with the HSTS header?"&gt;&lt;/a&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt; &lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt; &lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt; &lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt; &lt;div class="content"&gt; &lt;p&gt;Last Reviewed: August 2018&lt;/p&gt; &lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/13</link><pubDate>Wed, 12 Dec 2018 15:08:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 13 posted to Appian Knowledge Base by Jordan Horwat on 12/12/2018 3:08:59 PM&lt;br /&gt;
&lt;p&gt;Table of Contents&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#Does%20Appian%20support%20HSTS%20(HTTP%20Strict%20Transport%20Security)%20headers?"&gt;Does Appian support HSTS (HTTP Strict Transport Security) headers?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#How%20can%20I%20enable%20the%20HSTS%20header%20on%20Appian%20Cloud%20sites?"&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#How%20can%20I%20enable%20HSTS%20on%20Appian%20on-premise%20environments?"&gt;How can I enable HSTS on Appian on-premise environments?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#How%20do%20I%20confirm%20if%20my%20Appian%20site%20is%20enabled%20with%20the%20HSTS%20header?"&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="Does Appian support HSTS (HTTP Strict Transport Security) headers?"&gt;&lt;/a&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="How can I enable the HSTS header on Appian Cloud sites?"&gt;&lt;/a&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="How can I enable HSTS on Appian on-premise environments?"&gt;&lt;/a&gt;How can I enable HSTS on Appian on-premise environments?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="How do I confirm if my Appian site is enabled with the HSTS header?"&gt;&lt;/a&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/12</link><pubDate>Fri, 07 Dec 2018 15:15:12 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 12 posted to Appian Knowledge Base by Jordan Horwat on 12/7/2018 3:15:12 PM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/11</link><pubDate>Wed, 08 Aug 2018 02:28:40 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 11 posted to Appian Knowledge Base by Parmida Borhani on 8/8/2018 2:28:40 AM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/hsts.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/10</link><pubDate>Tue, 07 Aug 2018 22:28:40 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 10 posted to Appian Knowledge Base by Parmida Borhani on 8/7/2018 10:28:40 PM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/hsts.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/hsts.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>KB-1638 HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/9</link><pubDate>Tue, 07 Aug 2018 22:27:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 9 posted to Appian Knowledge Base by Parmida Borhani on 8/7/2018 10:27:58 PM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/hsts.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/hsts.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/8</link><pubDate>Tue, 07 Aug 2018 22:26:36 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 8 posted to Appian Knowledge Base by Parmida Borhani on 8/7/2018 10:26:36 PM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/hsts.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/hsts.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/7</link><pubDate>Tue, 07 Aug 2018 14:29:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Tejas Kargutkar</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 7 posted to Appian Knowledge Base by Tejas Kargutkar on 8/7/2018 2:29:58 PM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Please refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;You can use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/5153.HSTS_5F00_KB.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/5153.HSTS_5F00_KB.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, hsts, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/6</link><pubDate>Thu, 02 Aug 2018 11:41:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Tejas Kargutkar</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 6 posted to Appian Knowledge Base by Tejas Kargutkar on 8/2/2018 11:41:58 AM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Please refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;You can use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KBNew.PNG"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KBNew.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, hsts, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/5</link><pubDate>Wed, 01 Aug 2018 11:17:45 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Tejas Kargutkar</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 5 posted to Appian Knowledge Base by Tejas Kargutkar on 8/1/2018 11:17:45 AM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Please refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;You can use the browser network tool as seen in the following image to confirm whether HSTS is being used:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/2450.HSTS_5F00_KB.PNG"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/2450.HSTS_5F00_KB.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, hsts, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/4</link><pubDate>Wed, 01 Aug 2018 01:01:05 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 4 posted to Appian Knowledge Base by Parmida Borhani on 8/1/2018 1:01:05 AM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Please refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;You can use the browser network tool as seen in the following image to confirm whether HSTS is being used.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, hsts, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/3</link><pubDate>Wed, 01 Aug 2018 00:58:01 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 3 posted to Appian Knowledge Base by Parmida Borhani on 8/1/2018 12:58:01 AM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;Does Appian support HSTS (HTTP&amp;nbsp;Strict Transport Security) headers?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable the HSTS header on Appian Cloud sites?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How can I enable HSTS on Appian on-premise environments?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the web server that is being used with Appian. Please refer to the documentation of the respective web server to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&amp;nbsp;&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&amp;nbsp;&lt;/strong&gt;You can use the browser network tool as seen in the following image to confirm whether HSTS is being used.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, hsts, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/1</link><pubDate>Tue, 31 Jul 2018 21:41:29 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Tejas Kargutkar</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 1 posted to Appian Knowledge Base by Tejas Kargutkar on 7/31/2018 9:41:29 PM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;Does Appian support HSTS(HTTP&amp;nbsp;Strict Transport Security) header&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;How to enable the HSTS header on Appian Cloud sites ?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;How to enable HSTS on Appian on-premise environments:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the Web Server being used with Appian. Please refer to the documentation of the respective web server being used to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header ?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;You can use the browser network tool as seen in the following image to confirm whether HSTS is being used.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, hsts, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX HSTS FAQ</title><link>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq/revision/2</link><pubDate>Tue, 31 Jul 2018 17:46:52 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3b1b4d48-41a8-4f7f-9695-6d07ddcfece9</guid><dc:creator>Tejas Kargutkar</dc:creator><comments>https://community.appian.com/support/w/kb/1045/kb-1638-hsts-faq#comments</comments><description>Revision 2 posted to Appian Knowledge Base by Tejas Kargutkar on 7/31/2018 5:46:52 PM&lt;br /&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;Does Appian support HSTS(HTTP&amp;nbsp;Strict Transport Security) header ?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;How to enable the HSTS header on Appian Cloud sites ?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;This is enabled by default on Appian Cloud sites.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;How to enable HSTS on Appian on-premise environments:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;This&amp;nbsp;needs to be enabled on the Web Server being used with Appian. Please refer to the documentation of the respective web server being used to find out more on how to implement this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt;How do I confirm if my Appian site is enabled with the HSTS header ?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A:&lt;/strong&gt;You can use the browser network tool as seen in the following image to confirm whether HSTS is being used.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/HSTS_5F00_KB.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;div class="content"&gt;
&lt;p&gt;Last Reviewed:&amp;nbsp;July 2018&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: IIS, apache, web server, Security, hsts, infrastructure&lt;/div&gt;
</description></item></channel></rss>