HTTPS Strict Transport Security (HSTS)

  • KM03330525
  • 07-Feb-2019
  • 27-Feb-2019

Summary

Does UCMDB supports HTTPS Strict Transport Security (HSTS) ?

Question

Does UCMDB supports HTTPS Strict Transport Security (HSTS)  ?

Answer

1. By default UCMDB uses TLS1.2 so all other old protocols are disabled.
2. Officially we do not support HSTS. It is not mentioned in documentation and it was not tested. It might work as mentioned before there are some requirements for HSTS that are already implemented (header *Strict-Transport-Security: max-age=31536000*) but again it is not supported as it was not fully tested.