example.com.san_config file can interfere with the selected key algorithm during automatic renewal. DirectAdmin’s administration or migration process can remove this legacy file.DirectAdmin provides a Force Redirect function to select the canonical www or non-www hostname. The redirect works, but with the current Apache implementation an HTTPS 301 response can be generated without the security headers configured by the website in .htaccess.
Apache provides a relatively simple alternative that is not widely recognised: DirectAdmin’s existing rewrite can be placed in the existing <Directory> context of the normal HTTPS virtual host.
<Directory "/home/USER/domains/DOMAIN/public_html">
RewriteEngine On
RewriteCond %{HTTP_HOST} !^www\.DOMAIN$ [NC]
RewriteRule ^ https://www.DOMAIN%{REQUEST_URI} [R=301,L,NE]
</Directory>
DirectAdmin remains responsible for the Force Redirect and does not need to modify .htaccess. Apache can then apply the website’s existing security-header configuration to the redirect response.
On 24 September 2026 this was tested with webdomeindienst.nl, over both IPv4 and IPv6. With DirectAdmin’s Force Redirect moved from virtual-host rewrite context to the existing <Directory> context, the non-www 301 included the website’s existing Content-Security-Policy, X-Content-Type-Options, Referrer-Policy and X-Frame-Options.
The result was independently visible in the Multifold measurement at 15:05 UTC. (multifold.hostingtool.org)
After restoring DirectAdmin’s current configuration, those website headers disappeared from the 301 again while remaining present on the canonical www response. This provides a straightforward A/B/A test of the processing difference.
HSTS can also be application-managed. In particular, preload should not be added automatically when the domain-level HSTS configuration does not explicitly request it.
The demonstrated solution applies to Apache. With nginx + Apache, the determining question is whether nginx performs the canonical redirect before the request reaches Apache; if so, Apache and .htaccess cannot contribute to that response.
DirectAdmin’s OpenLiteSpeed template uses autoLoadHtaccess 1 together with FORCE_SSL_REDIRECT in its rewrite configuration. Its resulting behaviour should be tested separately rather than assumed to be identical to Apache or nginx.
For Apache, however, the test shows that no new “merged mode” is required. A small change in the processing context of DirectAdmin’s existing Force Redirect can preserve the separation between hosting-platform configuration and application configuration while allowing both to contribute correctly to the HTTPS response.