<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 'HSTS missing from HTTP' vulnerability (RFC 6797) in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435318#M26906</link>
    <description>&lt;P&gt;What other ports are you concerned about? HSTS headers are used to enforce the user of HTTPS (as opposed to HTTP). Other than the optional HTTP port enabled by the Qlik Proxy Service (80 by default), no other port used by Qlik Sense uses HTTP.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2024 18:53:39 GMT</pubDate>
    <dc:creator>Levi_Turner</dc:creator>
    <dc:date>2024-03-27T18:53:39Z</dc:date>
    <item>
      <title>'HSTS missing from HTTP' vulnerability (RFC 6797)</title>
      <link>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435226#M26903</link>
      <description>&lt;P&gt;hi, to be HSTS compliance, I followed the steps in article below.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/ta-p/1711505" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/ta-p/1711505&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;this is working fine for port 443. but we are using other ports as well and HSTS is not compliance to those ports.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to make QS compliance to HSTS to all ports (at least port we use).&lt;/P&gt;
&lt;P&gt;Can we mention ports in our header settings or in any other config files?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Strict-Transport-Security:&amp;nbsp;max-age=31536000;&amp;nbsp;includeSubDomains&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And there is another article to &lt;SPAN&gt;Redirect HTTP to HTTPS in Qlik Sense&lt;/SPAN&gt; on port 80. but I need for other ports as well.&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-Redirect-HTTP-to-HTTPS-in-Qlik-Sense/tac-p/2433345#M13568" target="_blank" rel="noopener"&gt;https://community.qlik.com/t5/Official-Support-Articles/How-to-Redirect-HTTP-to-HTTPS-in-Qlik-Sense/tac-p/2433345#M13568&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate your reply and any inputs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;found some related article to understand issue:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.tenable.com/plugins/nessus/142960" target="_blank" rel="noopener"&gt;https://www.tenable.com/plugins/nessus/142960&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://datatracker.ietf.org/doc/html/rfc6797" target="_blank" rel="noopener"&gt;https://datatracker.ietf.org/doc/html/rfc6797&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 14:35:56 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435226#M26903</guid>
      <dc:creator>Rajashekar</dc:creator>
      <dc:date>2024-03-27T14:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: 'HSTS missing from HTTP' vulnerability (RFC 6797)</title>
      <link>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435318#M26906</link>
      <description>&lt;P&gt;What other ports are you concerned about? HSTS headers are used to enforce the user of HTTPS (as opposed to HTTP). Other than the optional HTTP port enabled by the Qlik Proxy Service (80 by default), no other port used by Qlik Sense uses HTTP.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:53:39 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435318#M26906</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2024-03-27T18:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: 'HSTS missing from HTTP' vulnerability (RFC 6797)</title>
      <link>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435638#M26911</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/47469"&gt;@Levi_Turner&lt;/a&gt;&amp;nbsp;, thank you for your prompt response.&lt;/P&gt;
&lt;P&gt;ports 4242,4899, 4239 are still show "HSTS missing from HTTPS server" vulnerability (not compliant). not sure how to make these non vulnerable.&lt;/P&gt;
&lt;P&gt;Appreciate your response.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 13:26:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435638#M26911</guid>
      <dc:creator>Rajashekar</dc:creator>
      <dc:date>2024-03-28T13:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: 'HSTS missing from HTTP' vulnerability (RFC 6797)</title>
      <link>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435653#M26913</link>
      <description>&lt;P&gt;Those are internal ports which only operate using HTTPS. The point of HSTS is to ensure use of HTTPS. If you cannot use HTTP, then it is irrelevant for HSTS to ensure HTTPS use.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 13:58:09 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2435653#M26913</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2024-03-28T13:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: 'HSTS missing from HTTP' vulnerability (RFC 6797)</title>
      <link>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2476200#M27818</link>
      <description>&lt;P&gt;Hi Sir,&lt;/P&gt;
&lt;P&gt;I has the same question too, I used another product that is Qlik Replicate.&lt;BR /&gt;Follow document step to enable HSTS, but the port 3552 still show vulnerability (RFC 6797) by Vulnerability Assessment product.&lt;/P&gt;
&lt;P&gt;Please tell me how to solve it.&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 07:13:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/HSTS-missing-from-HTTP-vulnerability-RFC-6797/m-p/2476200#M27818</guid>
      <dc:creator>Aaron_Liu</dc:creator>
      <dc:date>2024-08-14T07:13:38Z</dc:date>
    </item>
  </channel>
</rss>

