# HSTS for Streaming Engine

**URL:** https://community.wowza.com/t/hsts-for-streaming-engine/97149
**Category:** Wowza Streaming Engine
**Tags:** ssl
**Created:** [April 4, 2024, 7:27am UTC](https://community.wowza.com/t/hsts-for-streaming-engine/97149 "2024-04-04T07:27:09Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Erwin\_Eggenberger1](https://avatars.discourse-cdn.com/v4/letter/e/dbc845/32.png) [@Erwin\_Eggenberger1](https://community.wowza.com/u/Erwin_Eggenberger1)
#### Post date: [April 4, 2024, 7:27am UTC](https://community.wowza.com/t/hsts-for-streaming-engine/97149/1 "2024-04-04T07:27:09Z")

</div>

Is there a way to enable HSTS for the Streaming Engine? It is mentioned in the docs for enabling HTTPS for the Manager ([https://www.wowza.com/docs/how-to-connect-to-wowza-streaming-engine-manager-over-https](https://www.wowza.com/docs/how-to-connect-to-wowza-streaming-engine-manager-over-https)), but I couldn’t find anything in the docs for the Streaming Engine.

---

<div class="post-metadata">

### Author: ![Alex\_C](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@Alex\_C](https://community.wowza.com/u/Alex_C)
#### Post date: [April 4, 2024, 2:18pm UTC](https://community.wowza.com/t/hsts-for-streaming-engine/97149/2 "2024-04-04T14:18:05Z")

</div>

Hi @Erwin_Eggenberger1,

You can add custom headers to HTTP responses via the following property

**Name: httpUserHTTPHeaders**  
**Path: /Root/Application/HTTPStreamer**  
**Type: String**  
**Value: Key:Value**

(where Key:Value = the header to add)

You can add multiple headers by delimiting them with the pipe (|) character.

You can optionally only add headers for particular playback types by changing the name to [lower-case-protocol-type]UserHTTPHeaders, e.g. for Apple HLS that would be cupertinoUserHTTPHeaders.

Here is an example

**httpUserHTTPHeaders**  
**strict-transport-security: max-age=31536000; includeSubDomains**  
**String**

Do note though that adding this HTTPStreamer property httpUserHTTPHeaders with the value of Strict-Transport-Security: max-age=31536000; includeSubDomains **will impact all HTTP requests to that application** (i.e. they would all have to be over HTTPS once the cookie is set on the client-side).

---

<div class="post-metadata">

### Author: ![Henrik\_Daschner](https://avatars.discourse-cdn.com/v4/letter/h/ecb155/32.png) [@Henrik\_Daschner](https://community.wowza.com/u/Henrik_Daschner)
#### Post date: [April 4, 2024, 9:14pm UTC](https://community.wowza.com/t/hsts-for-streaming-engine/97149/3 "2024-04-04T21:14:24Z")

</div>

Thanks, that works for applications. Should that also work for HTTPProviders? When I look at [https://www.wowza.com/docs/how-to-configure-date-headers-for-http-responses-from-http-providers](https://www.wowza.com/docs/how-to-configure-date-headers-for-http-responses-from-http-providers) it seems to be possible to set properties for providers, or even globally, but that didn’t seem to work with a **httpUserHTTPHeaders** property.
