Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Qlik and ServiceNow Partner to Bring Trusted Enterprise Context into AI-Powered Workflows. Learn More!
cancel
Showing results for 
Search instead for 
Did you mean: 
Kaushik2020
Creator III
Creator III

142960 - HSTS Missing From HTTPS Server (RFC 6797)

Hello Everyone, Just wondering if anyone have gone through the mentioned vulnerability. Here Cyber security team is doing a VAPT where they found these on the server where we have currently ONLY Qlik Sense running. 

I was exploring these in Chatgpt. below were the steps. 

You can add the HSTS header in the Virtual Proxy configuration.

Steps (QMC):

  1. Open QMC

  2. Go to Virtual Proxies

  3. Select the virtual proxy your users connect through (often “CentralProxy”)

  4. Scroll to Advanced

  5. In Additional response headers, add:

Strict-Transport-Security: max-age=31536000; includeSubDomains
  1. Ensure:

  • HTTPS enabled

  • HTTP disabled or redirected

  • Certificate valid

  1. Restart Qlik Proxy Service

Just wondering, if anyone have tried these before ? 

Thanks

3 Replies
Maria_Halley
Support
Support

Hi @Kaushik2020  It looks like Chatgpt found the correct information for you  . Here is a link to the Knowledge article we have about this. 

https://community.qlik.com/t5/Official-Support-Articles/HTTP-Strict-Transport-Security-HSTS-in-Qlik-...
Note that this will only affect connections through the proxy. Internal ports will not be affected. But they are already using https. 

 

Lily435
Contributor
Contributor

Hi @Kaushik2020  It looks like Chatgpt found the correct information for you  . Here is a link to the Knowledge article we have about this. 

Lily435
Contributor
Contributor

Hi @Kaushik2020  It looks like Chatgpt found the correct information for you  . Here is a link to the Knowledge article we have about this.