<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"><url>
    <loc>https://https-hardening.com/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/auditing-headers-with-curl-openssl-testssl/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/automated-header-scanning-in-ci-cd/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/csp-violation-reporting-and-monitoring/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/header-grading-observatory-and-securityheaders/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/security-header-audit-checklist/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cache-control-and-clear-site-data/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/content-security-policy-csp-essentials/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cross-origin-frame-controls-x-frame-options/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/deprecated-headers-legacy-browser-support/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cross-origin-isolation-coop-coep-corp/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/http-strict-transport-security-hsts-deep-dive/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/referrer-policy-permissions-policy-explained/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/apache-htaccess-virtualhost-hardening/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/cloudflare-page-rules-headers/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/fastapi-django-security-middleware/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/nginx-security-headers-configuration/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/nodejs-express-helmet-configuration/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/vercel-nextjs-header-management/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/csp-violation-reporting-and-monitoring/parsing-csp-violation-reports/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/security-header-auditing-and-compliance/header-grading-observatory-and-securityheaders/interpreting-securityheaders-com-grade/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cache-control-and-clear-site-data/cache-control-no-store-for-sensitive-pages/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cache-control-and-clear-site-data/using-clear-site-data-on-logout/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/content-security-policy-csp-essentials/csp-report-uri-vs-report-to-migration-guide/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/content-security-policy-csp-essentials/csp-strict-dynamic-explained/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/content-security-policy-csp-essentials/generating-csp-nonces-per-request/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/content-security-policy-csp-essentials/hash-based-csp-for-inline-scripts/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cross-origin-frame-controls-x-frame-options/fixing-x-frame-options-blocking-legitimate-iframes/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cross-origin-frame-controls-x-frame-options/x-frame-options-vs-csp-frame-ancestors-comparison/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/deprecated-headers-legacy-browser-support/removing-x-powered-by-and-server-headers-safely/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cross-origin-isolation-coop-coep-corp/debugging-coep-blocked-resources/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/cross-origin-isolation-coop-coep-corp/enabling-cross-origin-isolation-for-sharedarraybuffer/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/http-strict-transport-security-hsts-deep-dive/how-to-configure-max-age-and-includesubdomains-for-hsts/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/http-strict-transport-security-hsts-deep-dive/hsts-preload-vs-manual-enforcement-tradeoffs/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/referrer-policy-permissions-policy-explained/permissions-policy-disabling-browser-features/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/web-security-headers-fundamentals/referrer-policy-permissions-policy-explained/setting-referrer-policy-strict-origin-when-cross-origin/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/apache-htaccess-virtualhost-hardening/apache-mod_headers-best-practices-for-security/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/apache-htaccess-virtualhost-hardening/setting-csp-in-apache-htaccess/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/cloudflare-page-rules-headers/cloudflare-transform-rules-for-custom-security-headers/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/cloudflare-page-rules-headers/cloudflare-workers-for-security-headers/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/fastapi-django-security-middleware/adding-security-headers-in-fastapi-middleware/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/fastapi-django-security-middleware/django-security-middleware-vs-custom-headers/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/fastapi-django-security-middleware/setting-csp-in-django-middleware/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/nginx-security-headers-configuration/nginx-add-header-inheritance-in-location-blocks/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/nginx-security-headers-configuration/nginx-add_header-vs-proxy_hide_header-explained/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/nodejs-express-helmet-configuration/configuring-csp-with-helmet-and-nonces/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/vercel-nextjs-header-management/nextjs-nextconfigjs-headers-array-setup/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/vercel-nextjs-header-management/setting-csp-with-nonces-in-nextjs-middleware/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/server-platform-implementation-guides/vercel-nextjs-header-management/vercel-headers-json-vs-next-config-js/</loc>
    <lastmod>2026-06-19</lastmod>
  </url><url>
    <loc>https://https-hardening.com/</loc>
    <lastmod>2026-06-01</lastmod>
  </url>
</urlset>

