Can I turn on HSTS for 1 subdomain
Solution 1:
Yes.
Send the Strict-Transport-Security
header only for xxx.yyy.com
, and do not specify includeSubDomains
.
Browsers that properly handle HSTS will only set the requirement for the specified subdomain (xxx.yyy.com
) in this case.