<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Re: Enable HSTS for QEM and Replicate webapps - Status changed to: Closed - Already Available in Suggest an Idea</title>
    <link>https://community.qlik.com/t5/Suggest-an-Idea/Enable-HSTS-for-QEM-and-Replicate-webapps/idc-p/1821412#M6731</link>
    <description>&lt;P&gt;This capability was made available for Enterprise Manager in version 7 (Nov 2020) release.&amp;nbsp; Please refer to the following:&amp;nbsp;&lt;A href="https://help.qlik.com/en-US/enterprise-manager/May2021/Content/Global_Common/Content/SharedEMReplicate/Security/setting_hsts.htm" target="_blank"&gt;https://help.qlik.com/en-US/enterprise-manager/May2021/Content/Global_Common/Content/SharedEMReplicate/Security/setting_hsts.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jul 2021 12:12:55 GMT</pubDate>
    <dc:creator>Shelley_Brennan</dc:creator>
    <dc:date>2021-07-12T12:12:55Z</dc:date>
    <item>
      <title>Enable HSTS for QEM and Replicate webapps</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Enable-HSTS-for-QEM-and-Replicate-webapps/idi-p/1820518</link>
      <description>&lt;P&gt;The Replicate and QEM web applications do not enforce HTTP Strict Transport Security (HSTS).&lt;/P&gt;&lt;P&gt;The application should instruct web browsers to only access the application using HTTPS. To do this, enable HTTP Strict Transport Security (HSTS) by adding a response header with the name 'Strict-Transport-Security' and the value 'max-age=expireTime', where expireTime is the time in seconds that browsers should remember that the site should only be accessed using HTTPS. Consider adding the 'includeSubDomains' flag if appropriate.&lt;/P&gt;&lt;P&gt;This is a security best practice recommended by our penetration testing team.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 20:14:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Enable-HSTS-for-QEM-and-Replicate-webapps/idi-p/1820518</guid>
      <dc:creator>Prabodh</dc:creator>
      <dc:date>2021-07-07T20:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Enable HSTS for QEM and Replicate webapps - Status changed to: Closed - Already Available</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Enable-HSTS-for-QEM-and-Replicate-webapps/idc-p/1821412#M6731</link>
      <description>&lt;P&gt;This capability was made available for Enterprise Manager in version 7 (Nov 2020) release.&amp;nbsp; Please refer to the following:&amp;nbsp;&lt;A href="https://help.qlik.com/en-US/enterprise-manager/May2021/Content/Global_Common/Content/SharedEMReplicate/Security/setting_hsts.htm" target="_blank"&gt;https://help.qlik.com/en-US/enterprise-manager/May2021/Content/Global_Common/Content/SharedEMReplicate/Security/setting_hsts.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 12:12:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Enable-HSTS-for-QEM-and-Replicate-webapps/idc-p/1821412#M6731</guid>
      <dc:creator>Shelley_Brennan</dc:creator>
      <dc:date>2021-07-12T12:12:55Z</dc:date>
    </item>
  </channel>
</rss>

