Skip to content

The vCenter VAMI service must implement HTTP Strict Transport Security (HSTS).

An XCCDF Rule

Description

HSTS instructs web browsers to only use secure connections for all future requests when communicating with a website. Doing so helps prevent SSL protocol attacks, SSL stripping, cookie hijacking, and other attempts to circumvent SSL protection.

ID
SV-259157r935375_rule
Version
VCLD-80-000099
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Navigate to and open:

/etc/applmgmt/appliance/lighttpd.conf

Locate the "setenv.add-response-header" parameter and add or update the following value: