curl-curl/docs/HSTS.md
Daniel Stenberg 93e80c75b4
hsts: accept 10K entries in the list
Up from 1K.

Reduces the risk that someone could flush the list by tricking a user to
do many transfers to new hostnames.

Document the limit.

Follow-up to 03a792b186

Closes #21200
2026-04-02 10:22:35 +02:00

1.3 KiB

HSTS support

HTTP Strict-Transport-Security. Added as experimental in curl 7.74.0. Supported "for real" since 7.77.0.

Standard

HTTP Strict Transport Security

Behavior

libcurl features an in-memory cache for HSTS hosts, so that subsequent HTTP-only requests to a hostname present in the cache gets internally "redirected" to the HTTPS version.

Since curl 8.20.0, libcurl keeps no more than the most recently added 10,000 unique HSTS hostnames.

curl_easy_setopt() options:

  • CURLOPT_HSTS_CTRL - enable HSTS for this easy handle
  • CURLOPT_HSTS - specify filename where to store the HSTS cache on close (and possibly read from at startup)

curl command line options

  • --hsts [filename] - enable HSTS, use the file as HSTS cache. If filename is "" (no length) then no file is used, only in-memory cache.

HSTS cache file format

Lines starting with # are ignored.

For each hsts entry:

[hostname] "YYYYMMDD HH:MM:SS"

The [hostname] is dot-prefixed if it includes subdomains.

The time stamp is when the entry expires.

Possible future additions

  • CURLOPT_HSTS_PRELOAD - provide a set of HSTS hostnames to load first
  • ability to save to something else than a file