Enabling HTTP Strict-Transport-Security (HSTS) in HTTP-Header in JBoss EAP
Issue
- How to avoid a man in the middle vulnerability for HTTPS Cookie Injection Vulnerability
- How to enable HTTP Strict-Transport-Security (HSTS) in HTTP-Header for security
- Is HSTS (Http Strict Transport Security) support available on jboss 5.1.0.GA?
Environment
- Red Hat JBoss Enterprise Application Platform
- 6.x
- 5.x
- 4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.