It's important for this policy to appear on the root https://everykidinapark.gov, and not only on the www subdomain.
The current policy is our Cloud Foundry default, which lacks the ; includeSubDomains; preload part. Cloud Foundry is designed to pass on an app's own HSTS policy if it sets one itself, so an override by EKIP will show up on the public internet.
As recommended by OMB, for a second-level domain like everykidsinapark.gov, it's preferable (and awesome) to add an HSTS policy of:
It's important for this policy to appear on the root
https://everykidinapark.gov
, and not only on thewww
subdomain.The current policy is our Cloud Foundry default, which lacks the
; includeSubDomains; preload
part. Cloud Foundry is designed to pass on an app's own HSTS policy if it sets one itself, so an override by EKIP will show up on the public internet.