Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 
nilesh007
Partner - Creator

CSP Content-Security-Policy header issue

Hi Community,

In Qlik sense enterprise, according to VAPT report there are some missing security headers which needs to be implemented. We are facing issue while adding the below security header in the virtual proxy.
--> Content-Security-Policy: default-src 'self'
After implementing it we are unable to access qlik getting black/grey screen.

Articles followed:

https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Securing-an....

How to determine string policy for Content Securit... - Qlik Community - 1715491

 

error5.JPGnetwork.JPG

3 Replies
Ray_Strother
Support

Hello ,

Not sure if this is what you are looking . adding additional response headers : https://community.qlik.com/t5/Official-Support-Articles/How-to-add-additional-response-headers-in-Ql...
bella964
Contributor

Hello,
Can u pls explain me more about this.
safeco now agent login
Best Regards

nilesh007
Partner - Creator
Author

Hi Ray,

Thanks for your reply. We want this header to be implemented in the virtual proxy "Content-Security-Policy: default-src 'self'" before making it live on the Internet. But according to the VAPT report, if we do not implement this header, it is not safe to make it live. We tried implementing this header, but QMC and Hub are not working after that.