In Password Manager 5.15, HSTS (Strict HTTP) is enabled by default. This means that a certificate is required to be installed on the Password Manager servers and configured in IIS before proceeding with an installation or upgrade.
While One Identity cannot assist with the Certificate creation or request portion, the steps outlined below cover the core requirements for the Certificate and how to apply it on the Password Manager server.
NOTE: For testing purposes, HSTS can be disabled in order to access the Password Manager sites without using HTTPS. To do so:
Core Certificate Requirements:
Pre-Installation Checklist:
Post-Installation:
EXAMPLE CERTIFICATE AND CONFIGURATION
NOTE: This example is for a domain called "demo2.lab". The two Password Manager servers are demo2app7 and demo2app8.
Certificate Details

IIS BINDING:
PASSWORD MANAGER:
© 2025 One Identity LLC. ALL RIGHTS RESERVED. 利用規約 プライバシー Cookies Preference Center