In the Optimisation tab you determine how content reaches your visitors' browsers. Changes take effect with Apply.
Protocols
- HTTP/1.1 for older programs and tools - always available.
- HTTP/2 transfers several files simultaneously over one connection. It is used by all current browsers and is permanently switched on for all sites.
- Offer HTTP/3 with QUIC (on by default): the latest protocol over UDP with faster connection setup and stable on changing networks, for example on mobile. ShieldCache announces it to browsers, which then switch over themselves.
Only switch off HTTP/3 if visitors behind firewalls have problems with UDP. ShieldCache then no longer announces it; browsers that already know HTTP/3 for your domain can still use it for up to 30 days. Encryption uses TLS 1.2 and 1.3 - always active.
Compression
The default is off: responses arrive as your server delivers them - most servers already compress them themselves. When switched on, ShieldCache compresses responses of 512 bytes or more with Zstandard or gzip if the browser supports it and the response is not yet compressed.
Compression and secret form values
If your website outputs secret values, such as form tokens, together with visitor input, compression over HTTPS can make attacks such as BREACH easier. In that case, leave compression off unless your server compresses anyway.
HSTS
With HSTS, browsers only connect to your domain via HTTPS. The default is “As the security headers”: the templates Standard, Static content and With HTTPS upgrade set HSTS for one year with subdomains and preload, while the “None” template sets no HSTS. Separately from this, you choose here:
- Off: ShieldCache does not set HSTS. With the “None” template, an HSTS header from your server is retained.
- On: HTTPS only for one year for this domain, without subdomains.
- On with subdomains and preload: HTTPS only for one year for the domain and all subdomains, suitable for the browsers' preload list.
Be careful with preload
With preload, browsers require HTTPS for all subdomains - including those that do not run via ShieldCache. Choose “On” if a subdomain still needs to be reachable without HTTPS.
Security headers and file protection
In the Settings tab, General sub-tab, choose a template for the security headers under Redirect and security:
- Standard: HSTS, protection against clickjacking and MIME sniffing, restricted browser permissions. Right for most websites.
- Static content: like Standard, but without embedding protection and with sharing enabled for other websites - for images, scripts and fonts that other sites include.
- With HTTPS upgrade: like Standard, plus a Content Security Policy that automatically loads insecurely included http content via HTTPS (mixed content).
- None: ShieldCache does not set any headers of its own, and those from your origin remain.
The selected template replaces headers of the same name from your server. You set up custom headers and your own Content Security Policy in addition - see Content Security Policy and custom headers.
In the same area you will find the www redirect (none, to www or without www - both domains must be added) and file protection. File protection blocks access to sensitive files such as configuration, backups and version control - with profiles for WordPress, WooCommerce, Shopware, Joomla, Laravel and other applications. Blocked requests receive the error page SC-403-DATEI.