# HSTS Preload Submission - Error: HTTP redirects to www first

**URL:** https://discourse.roots.io/t/hsts-preload-submission-error-http-redirects-to-www-first/20717
**Category:** trellis
**Created:** 2021-05-04T14:36:48Z
**Posts:** 4

## Post 1 by @sorendam — 2021-05-04T14:36:48Z

I get an error when I try to submit my site to [hstspreload.org](http://hstspreload.org). as the site redirects directly from [http://mydomain.com](http://mydomain.com) to [https://www.mydomain.com](https://www.mydomain.com) instead of [http://mydomain.com](http://mydomain.com) to [https://mydomain.com](https://mydomain.com) and then finally to [https://www.mydomain.com](https://www.mydomain.com).

 ![Screenshot 2021-05-04 at 16.27.52](https://discourse.roots.io/uploads/default/original/2X/a/ad5d45a8800757920f72bf573465831cd5d0fcb6.png)

Does anybody know how to change the setup so this issue is resolved?

---

## Post 2 by @strarsis — 2021-05-04T15:19:58Z

Are you using [roots.io](http://roots.io) Trellis? I guess you are already using [roots.io](http://roots.io) Bedrock and [roots.io](http://roots.io) Sage.

> <https://github.com/roots/trellis/blob/17430191bb7211545eb63ba3ba989ee95c262c5f/roles/wordpress-setup/templates/wordpress-site.conf.j2#L282>

---

## Post 3 by @sorendam — 2021-05-04T20:08:37Z

Yes I’m on Trellis, Bedrock and Sage. Latest versions except Sage which is version 9. From the wordpress-site.conf.j2 file It looks like this is indeed redirecting from [http://mysite.com](http://mysite.com) directly to [https://www.mysite.com](https://www.mysite.com) when I have set up my wordpress\_sites.yml like this:

 ![Screenshot 2021-05-04 at 21.57.09](https://discourse.roots.io/uploads/default/original/2X/2/221d50959faff7916b044f1ec89c8774641b4c13.png)

However, I am not sure how to change this configuration in order to make this redirect to https before redirecting to www. Also, this is probably a general issue when having hsts preload enabled and using a subdomain like www as the canonical domain.

---

## Post 4 by @strarsis — 2021-05-04T20:29:27Z

Using your configuration above Trellis/ansible generates nginx configuration.  
You can check the resulting nginx configuration on the actual server after the playbook has been applied.  
There are nginx blocks for redirecting from non-www to www and also one for redirecting from non-https to https. You have to ensure that the block for redirecting from non-https to https takes precedence over the other blocks for that site. For making this permanent you will have to adjust your Trellis project and change the nginx template.

This seems to improve security - on the other hand it also seems to add a performance penalty as now two redirects are required in the worst case: One from non-https to https, then one from non-ww to www (for example).

---

## Post 5 by @system — 2021-06-15T14:38:08Z

This topic was automatically closed after 42 days. New replies are no longer allowed.
