HTTP Strict-Transport-Security Header in Liferay
knowledge-article-header-disclaimer-how-to
knowledge-article-header-disclaimer
legacy-article
learn-legacy-article-disclaimer-text
Issue
- Is HTTP Strict-Transport-Security Header enabled in Liferay?
Resolution
- Liferay enables HTTP security headers such as 'http.header.secure.x.content.type.options', 'http.header.secure.x.xss.protection', 'http.header.secure.x.content.type.options' by default.
- The HTTP Strict-Transport-Security Header is not enabled in Liferay as the required configuration should be performed on an Application Server like Tomcat or the WebServer like Apache.
- However, there is a feature request for enabling the HSTS Header at Liferay's end. Please refer to the LPS-39213 and can vote on the LPS, so that if the feature is implemented you will come to know.
did-this-article-resolve-your-issue