Symptom
This note helps you configure HTTP Strict Transport Security (HSTS) which is recommended to protect your web sites against protocol downgrade attacks and cookie hijacking.
- Insecure communication over HTTP
- HSTS option missing in header
Read more...
Environment
SAP NetWeaver 7.1 or higher
Product
SAP NetWeaver 7.0 ; SAP NetWeaver 7.1 ; SAP NetWeaver 7.2 ; SAP NetWeaver 7.3 ; SAP NetWeaver 7.4 ; SAP NetWeaver 7.5 ; SAP enhancement package 1 for SAP NetWeaver 7.0 ; SAP enhancement package 1 for SAP NetWeaver 7.3 ; SAP enhancement package 2 for SAP NetWeaver 7.0 ; SAP enhancement package 3 for SAP NetWeaver 7.0
Keywords
TLS, SSL, HTTP Strict Transport Security (HSTS), IIS , KBA , BC-SEC-WSS , Web Services Security for ABAP , BC-SEC-SSL , Secure Sockets Layer Protocol , How To
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.