> Neither provides the HSTS header to an unauthenticated user. Is there > a simple way to inject the HSTS (or any) header to unauthenticated > users? If it's the 401 that you want to have the header, you'll need Header always set ... --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx