Re: Is it possible to add hsts header over http response ?

2023-01-13 Thread Christopher Schultz
Shawn, On 1/12/23 20:48, Shawn Heisey wrote: On 1/12/23 01:34, Mark Thomas wrote: On 12/01/2023 08:26, Hiran CHAUDHURI wrote: In that case the Connector would need to be configured with secure="true" to work correctly/securely and the HttpHeaderSecurityFilter would add the HSTS header if conf

Re: Is it possible to add hsts header over http response ?

2023-01-12 Thread Shawn Heisey
On 1/12/23 01:34, Mark Thomas wrote: On 12/01/2023 08:26, Hiran CHAUDHURI wrote: In that case the Connector would need to be configured with secure="true" to work correctly/securely and the HttpHeaderSecurityFilter would add the HSTS header if configured to do so. My personal opinion is that

Re: Is it possible to add hsts header over http response ?

2023-01-12 Thread Mark Thomas
On 12/01/2023 08:26, Hiran CHAUDHURI wrote: CONFIDENTIAL & RESTRICTED Would/should this also cover cases where Tomcat is working on http or ajp although the connection is considered secure as SSL is offloaded to httpd or some other reverse proxy? In that case the Connector would need to be c

RE: Is it possible to add hsts header over http response ?

2023-01-12 Thread Hiran CHAUDHURI
CONFIDENTIAL & RESTRICTED Would/should this also cover cases where Tomcat is working on http or ajp although the connection is considered secure as SSL is offloaded to httpd or some other reverse proxy? -Original Message- From: Thomas Hoffmann (Speed4Trade GmbH) Sent: Thursday, Januar