HTTPS-only and HSTS
⧼vector-appearance-label⧽
[Category:Authentication]]
Google Best Practices for HTTPS
That following are the best practice specified by Google (https://support.google.com/webmasters/answer/6073543?hl=en&ref_topic=6001951)
- HSTS Headers on HTTPS
- No “Mixed Content” warnings/errors
- Links point to HTTPS locations
- 301 Redirects from HTTP to HTTPS