Re: Http insecure headers

2019-03-05 Thread Peter@Kreuser-Online
Nitin, sorry for my late reply. > Am 27.02.2019 um 17:01 schrieb Nitin Kadam : > > Hello , > > We dint have any reverse proxy in middle layers and we have added filters in > web.config only, Please find attached snaps of same. > i am new to tomcat so didnt able to understand all terms. >

Re: Http insecure headers

2019-02-27 Thread Nitin Kadam
Hello , We dint have any reverse proxy in middle layers and we have added filters in web.config only, Please find attached snaps of same. i am new to tomcat so didnt able to understand all terms. On Wed, Feb 27, 2019 at 9:20 PM logo wrote: > > > Hello Nitin, > > Am 27.02.2019 16:34, schrieb

Re: Http insecure headers

2019-02-27 Thread logo
Hello Nitin, Am 27.02.2019 16:34, schrieb Nitin Kadam: > Hello Team, > > I have added below given filter and restarted tomcat service still it shows > Cache Control as private. > Please help me on same. Pictures are stripped off the mailing list. so better send us text logs.

Re: Http insecure headers

2019-02-27 Thread Nitin Kadam
Hello Team, I have added below given filter and restarted tomcat service still it shows Cache Control as private. Please help me on same. [image: image.png] On Wed, Feb 27, 2019 at 2:54 PM logo wrote: > Hi Nitin, > > Am 27.02.2019 10:11, schrieb Nitin Kadam: > > Sorry for typo in earlier

Re: Http insecure headers

2019-02-27 Thread logo
Hi Nitin, Am 27.02.2019 10:11, schrieb Nitin Kadam: Sorry for typo in earlier email, i was saying about ExpiresFilter only so how do i add this filter and failter mapping , Do i need to add both in existing httpHeaderSecurity ExpiresFilter org.apache.catalina.filters.ExpiresFilter

Re: Http insecure headers

2019-02-27 Thread Nitin Kadam
Sorry for typo in earlier email, i was saying about ExpiresFilter only so how do i add this filter and failter mapping , Do i need to add both in existing httpHeaderSecurity ExpiresFilter org.apache.catalina.filters.ExpiresFilter ExpiresByType image access plus 10

Re: Http insecure headers

2019-02-27 Thread logo
Hello Nitin, Am 27.02.2019 08:52, schrieb Nitin Kadam: Hello, How can i change “Cache Control -private: to “Cache-Control: nostore” i searched and found that need to add express filters in web config but not sure on where to add in filters. can you please guide me on same? as far as I

Re: Http insecure headers

2019-02-26 Thread Nitin Kadam
Hello, How can i change “Cache Control -private: to “Cache-Control: nostore” i searched and found that need to add express filters in web config but not sure on where to add in filters. can you please guide me on same? On Wed, Feb 20, 2019 at 3:28 AM Peter@Kreuser-Online wrote: > Hi

Re: Http insecure headers

2019-02-19 Thread Peter@Kreuser-Online
Hi Nitin, Per se this can be done by enabling the org.apache.catalina.filters.HttpHeaderSecurityFilter in the global or your webapp‘s web.xml For CSP you should write your own Filter. Beware though that Content Security Policy is nothing that can be enabled without application knowhow, the

Http insecure headers

2019-02-19 Thread Nitin Kadam
Hello Team Need help to enable below security headers in Apache tomcat 7.0.79 Operating system is windows 2012 R2 1. Content security headers 2. HSTS header Regards Nitin