<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article HTTP Strict Transport Security (HSTS) in Qlik Sense in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/ta-p/1711505</link>
    <description>&lt;P&gt;HTTP Strict Transport Security (HSTS) is an opt-in security enhancement which any web application can support through the use of a special response header. When a supported browser receives this header that browser will prevent any communication sent over HTTP in the future and will redirect all traffic over HTTPS instead.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;More details about HSTS can be found on&amp;nbsp;&lt;A href="https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Strict_Transport_Security_Cheat_Sheet.html" target="_blank" rel="noopener"&gt;https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Strict_Transport_Security_Cheat_Sheet.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Qlik Sense,&amp;nbsp;one can add&amp;nbsp;additional HTTP response headers in the Virtual Proxy configuration to enforce&amp;nbsp;HSTS&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the Qlik Sense QMC&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In the CONFIGURATION SYSTEM section,&amp;nbsp; click on Virtual Proxies&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Select the Virtual Proxy profile&amp;nbsp;for user access and click on Edit&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Go to the Advanced section and in the field "Additional response headers"&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Enter the HSTS configuration setting applicable to your environment. i.e&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="emailMessageFeedItemBody"&gt;&lt;SPAN class="emailMessageBody"&gt;Strict-Transport-Security: max-age=31536000;includeSubDomains;Preload&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="virtual proxy settings.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/88777i3D4417B69262691E/image-size/large?v=v2&amp;amp;px=999" role="button" title="virtual proxy settings.png" alt="virtual proxy settings.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;HTTP to HTTPS must be enabled.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;For additional information about HTTP to HTTPS redirects, see&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/How-to-Redirect-HTTP-to-HTTPS-in-Qlik-Sense/ta-p/1716920" target="_blank" rel="noopener"&gt;How to: Redirect HTTP to HTTPS in Qlik Sense&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://community.qlik.com/t5/Qlik-Sense-Deployment-Management/Qlik-Sense-redirect-HTTP-to-HTTPS/m-p/53978" target="_blank" rel="noopener"&gt;Qlik Community:&amp;nbsp;Qlik Sense redirect HTTP to HTTPS&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;and feature request&amp;nbsp;&lt;A href="https://support.qlik.com/articles/Basic/Sense-Initial-redirect-to-hub-http" target="_blank" rel="noopener"&gt;Sense Initial URL redirect to /hub (http)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Sites to Confirm HSTS setup&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://hstspreload.org/" target="_blank" rel="noopener"&gt;https://hstspreload.org/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://tools.geekflare.com/hsts-test" target="_blank" rel="noopener"&gt;https://tools.geekflare.com/hsts-test&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://dev.ssllabs.com/ssltest/" target="_blank" rel="noopener"&gt;https://dev.ssllabs.com/ssltest/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://nvisium.com/blog/2014/04/25/is-your-site-hsts-enabled.html" target="_blank" rel="noopener"&gt;https://nvisium.com/blog/2014/04/25/is-your-site-hsts-enabled.html&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Gov Site on HSTS&amp;nbsp; &lt;A href="https://https.cio.gov/hsts/" target="_blank" rel="noopener"&gt;https://https.cio.gov/hsts/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&amp;nbsp;Qlik does&amp;nbsp;&lt;STRONG&gt;NOT&lt;/STRONG&gt;&amp;nbsp;support the configuration or implementation of non-Qlik or Operating System related software. The above suggestion is an introduction to this topic, and if it does not work in your particular environment then please reach out internally to your IT team. If you need direct assistance, please contact your Account Owner to discuss purchasing Consulting Services. (see&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-and-When-to-Contact-the-Consulting-Team/ta-p/1714936" target="_blank" rel="noopener"&gt;How to Contact the Consulting Team?&lt;/A&gt;)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2022 07:51:29 GMT</pubDate>
    <dc:creator>Sonja_Bauernfeind</dc:creator>
    <dc:date>2022-09-09T07:51:29Z</dc:date>
    <item>
      <title>HTTP Strict Transport Security (HSTS) in Qlik Sense</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/ta-p/1711505</link>
      <description>&lt;P&gt;HTTP Strict Transport Security (HSTS) is an opt-in security enhancement which any web application can support through the use of a special response header. When a supported browser receives this header that browser will prevent any communication sent over HTTP in the future and will redirect all traffic over HTTPS instead.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;More details about HSTS can be found on&amp;nbsp;&lt;A href="https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Strict_Transport_Security_Cheat_Sheet.html" target="_blank" rel="noopener"&gt;https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Strict_Transport_Security_Cheat_Sheet.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Qlik Sense,&amp;nbsp;one can add&amp;nbsp;additional HTTP response headers in the Virtual Proxy configuration to enforce&amp;nbsp;HSTS&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the Qlik Sense QMC&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In the CONFIGURATION SYSTEM section,&amp;nbsp; click on Virtual Proxies&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Select the Virtual Proxy profile&amp;nbsp;for user access and click on Edit&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Go to the Advanced section and in the field "Additional response headers"&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Enter the HSTS configuration setting applicable to your environment. i.e&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="emailMessageFeedItemBody"&gt;&lt;SPAN class="emailMessageBody"&gt;Strict-Transport-Security: max-age=31536000;includeSubDomains;Preload&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="virtual proxy settings.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/88777i3D4417B69262691E/image-size/large?v=v2&amp;amp;px=999" role="button" title="virtual proxy settings.png" alt="virtual proxy settings.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;HTTP to HTTPS must be enabled.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;For additional information about HTTP to HTTPS redirects, see&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/How-to-Redirect-HTTP-to-HTTPS-in-Qlik-Sense/ta-p/1716920" target="_blank" rel="noopener"&gt;How to: Redirect HTTP to HTTPS in Qlik Sense&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://community.qlik.com/t5/Qlik-Sense-Deployment-Management/Qlik-Sense-redirect-HTTP-to-HTTPS/m-p/53978" target="_blank" rel="noopener"&gt;Qlik Community:&amp;nbsp;Qlik Sense redirect HTTP to HTTPS&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;and feature request&amp;nbsp;&lt;A href="https://support.qlik.com/articles/Basic/Sense-Initial-redirect-to-hub-http" target="_blank" rel="noopener"&gt;Sense Initial URL redirect to /hub (http)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Sites to Confirm HSTS setup&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://hstspreload.org/" target="_blank" rel="noopener"&gt;https://hstspreload.org/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://tools.geekflare.com/hsts-test" target="_blank" rel="noopener"&gt;https://tools.geekflare.com/hsts-test&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://dev.ssllabs.com/ssltest/" target="_blank" rel="noopener"&gt;https://dev.ssllabs.com/ssltest/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://nvisium.com/blog/2014/04/25/is-your-site-hsts-enabled.html" target="_blank" rel="noopener"&gt;https://nvisium.com/blog/2014/04/25/is-your-site-hsts-enabled.html&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Gov Site on HSTS&amp;nbsp; &lt;A href="https://https.cio.gov/hsts/" target="_blank" rel="noopener"&gt;https://https.cio.gov/hsts/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&amp;nbsp;Qlik does&amp;nbsp;&lt;STRONG&gt;NOT&lt;/STRONG&gt;&amp;nbsp;support the configuration or implementation of non-Qlik or Operating System related software. The above suggestion is an introduction to this topic, and if it does not work in your particular environment then please reach out internally to your IT team. If you need direct assistance, please contact your Account Owner to discuss purchasing Consulting Services. (see&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-and-When-to-Contact-the-Consulting-Team/ta-p/1714936" target="_blank" rel="noopener"&gt;How to Contact the Consulting Team?&lt;/A&gt;)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 07:51:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/ta-p/1711505</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2022-09-09T07:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Strict Transport Security (HSTS) in Qlik Sense</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2460573#M14064</link>
      <description>&lt;P&gt;I understand that the above configuration is for connections via a proxy, and connections to ports like 4242 and 4239 should not be user-facing through a browser. Our client has identified a vulnerability indicating that the remote web server is not enforcing HSTS, as defined by RFC 6797, on ports 4242, 4239, and 4899. Is it possible to address this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 05:32:47 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2460573#M14064</guid>
      <dc:creator>fabdulazeez</dc:creator>
      <dc:date>2024-06-10T05:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Strict Transport Security (HSTS) in Qlik Sense</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2460672#M14068</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/10066"&gt;@fabdulazeez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have identified a security concern, please report your concern as a support case as per &lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Security-Vulnerability-Policy/ta-p/1713629" target="_blank" rel="noopener"&gt;Qlik Security Vulnerability Policy&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;All the best,&lt;BR /&gt;Sonja&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 10:11:27 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2460672#M14068</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2024-06-10T10:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Strict Transport Security (HSTS) in Qlik Sense</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2460680#M14070</link>
      <description>&lt;DIV class="flex-shrink-0 flex flex-col relative items-end"&gt;
&lt;DIV&gt;
&lt;DIV class="pt-0.5 juice:pt-0"&gt;
&lt;DIV class="gizmo-bot-avatar flex h-6 w-6 items-center justify-center overflow-hidden rounded-full juice:h-8 juice:w-8"&gt;
&lt;DIV class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="group/conversation-turn relative flex w-full min-w-0 flex-col agent-turn"&gt;
&lt;DIV class="flex-col gap-1 md:gap-3"&gt;
&lt;DIV class="flex flex-grow flex-col max-w-full"&gt;
&lt;DIV class="min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2" dir="auto" data-message-author-role="assistant" data-message-id="1560637d-23a6-4825-9a3b-92d8fa5e7f43"&gt;
&lt;DIV class="flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;Sorry for the incorrect word in the previous query. I meant that the client has shared a vulnerability, "HSTS Missing From HTTPS Server (RFC 6797)," for ports 4239, 4242, and 4899.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 10 Jun 2024 10:27:39 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2460680#M14070</guid>
      <dc:creator>fabdulazeez</dc:creator>
      <dc:date>2024-06-10T10:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Strict Transport Security (HSTS) in Qlik Sense</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2499426#M15170</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/10066"&gt;@fabdulazeez&lt;/a&gt;&amp;nbsp;, I got the Same&amp;nbsp;&lt;SPAN&gt;vulnerability raise from the Client side, do you have any workaround for this? Any Help from the Qlik Side on this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 09:51:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-Sense/tac-p/2499426#M15170</guid>
      <dc:creator>atiwari</dc:creator>
      <dc:date>2024-12-27T09:51:40Z</dc:date>
    </item>
  </channel>
</rss>

