The vCenter VAMI service must implement HTTP Strict Transport Security (HSTS).
An XCCDF Rule
Description
HSTS instructs web browsers to only use secure connections for all future requests when communicating with a website. Doing so helps prevent SSL protocol attacks, SSL stripping, cookie hijacking, and other attempts to circumvent SSL protection.
- ID
- SV-259157r935375_rule
- Version
- VCLD-80-000099
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Navigate to and open:
/etc/applmgmt/appliance/lighttpd.conf
Locate the "setenv.add-response-header" parameter and add or update the following value: