3 ms·
As per the spec, setting max-age=0 disables HSTS.
by hdevalence 13y ago
As per the spec, setting max-age=0 disables HSTS.
- deathanatos 13y agoYes, but you'd have to serve that over HTTPS. And even then, how do you know that all the caches that have the older, longer expiration time have revisited and updated their cache? You won't, really, until that many seconds have pass.
- hdevalence 13y agoRight, my point was just that there is a specified way for the server to tell the client not to use HSTS any more. Of course, the caveats you mention mean that to be certain, you would need to wait.