The header becomes a remembered HTTPS rule for the host.

highlighted = computed this step

The host gets an HTTPS rule

The remembered-rule rows tie the rule to the same pinned host.

secure.example remembers HTTPS\text{secure.example remembers HTTPS}
Remembered ruleThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.Remembered rule - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

The rule lasts for the max-age duration

The remembered seconds row repeats the parsed max-age value.

remember seconds=60\text{remember seconds}=60
Remembered ruleThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.Remembered rule - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

The rule is derived from the header

The page shows the remembered rule only after the header bytes validate.

headerremember rule\text{header} \rightarrow \text{remember rule}
Remembered ruleThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.Remembered rule - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

Summary

The toy browser-side memory is represented as a static validated row.

remembered rule checked\text{remembered rule checked}
Remembered ruleThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.Remembered rule - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty