cancel
Showing results for 
Search instead for 
Did you mean: 

HSTS support

ITdept_
Contributor

HSTS support

Hi,

 

Does anyone know if HSTS Strict Transport Security is supported on the SA? I understand most major browsers support it now and it seems the best way currently to prevent sslstrip MitM attacks.

 

http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security

1 REPLY 1
zanyterp_
Respected Contributor

Re: HSTS support

No, you will need an enhancement request for that.
In the meantime, it looks like you can achieve similar by making sure your firewall does not allow HTTP to HTTPS redirection and setting the IVE security settings to not allow weak ciphers