# Do not use header always set, it would push HSTS to non-HTTPS even though it's in this tree... Header set Strict-Transport-Security "max-age=31556926;includeSubDomains;preload"