The host row names the site that can receive the rule.

highlighted = computed this step

The request names secure.example

The Host header is the site that can receive the HSTS rule.

Host=secure.example\text{Host}=\text{secure.example}
Request hostThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Request host - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

The path is the root path

This toy request only needs the host and one small path.

path=/\text{path}=\text{/}
Request hostThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Request host - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

The request body is empty

The blank line ends the headers in this pinned GET request.

request rows checked\text{request rows checked}
Request hostThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Request host - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

Summary

The HSTS rule belongs to the exact host in the request row.

host checked\text{host checked}
Request hostThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Request host - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty