Configuring HTTP strict transport security headers - Platform - BlueCat Gateway - 25.3.0

Gateway Administration Guide

ft:locale
en-US
Product name
BlueCat Gateway
Version
25.3.0

Within Security settings in the General Configuration page, you can configure strict transport security (strict-transport-security) response headers. This is an HTTP response header that lets Gateway webpages tell browsers that it should be accessed only with the HTTPS protocol, and not with HTTP.

Attention: As a security best practice, BlueCat strongly recommends enabling this option.

For more information on Strict Transport Security response headers, see Strict-Transport-Security on the Mozilla website.

To configure Gateway security response headers:

  1. Open the General configuration window, then expand the Security section. (Click Settings at the bottom of the navigator on the left, expand Configurations, then click General configuration. Click Security to scroll to the Security section.)

  2. Scroll down to the HTTP strict transport security section, then configure the settings as desired.

    For more details, see Cross-origin resource sharing (CORS) settings list below.

  3. When you're done, click Save changes.

    To cancel your changes, click Cancel.

Transport security response header settings list

The Transport security response header section has the following settings.

Setting Description
Strict Transport Security

If ticked, the use of strict-transport-security response headers is enabled. This header tells browsers that the page should only be accessed using HTTPS.

Max age

The number of seconds that the browser should remember that the site should be restricted to HTTPS.

The default value is 31556926 seconds (or 365 days).

Include subdomains

If ticked, the rule will apply to all of the site's subdomains.