-
Feature Request
-
Resolution: Done
-
Major
-
None
-
None
-
None
-
False
-
None
-
False
-
Not Selected
-
-
-
1. Proposed title of this feature request
Allow for Openshift Authentication to be configured for HSTS (HTTP Strict Transport Security)
2. What is the nature and description of the request?
Some infrastructures require that HSTS be set for all endpoints. For cluster components, this can be achieved with the route if it is edge or re-encrypt. However, auth is the only one that uses passthrough. Therefore, the only way to set up HSTS here would be through the authentication application itself.
3. Why does the customer need this? (List the business requirements here)
Infrastructure security requirement.
4. List any affected packages or components.
Openshift Authentication
Openshift Authentication Operator
Note:
There exists igress configuration for HSTS, this should be honored to address this RFE properly.
- is duplicated by
-
RFE-2841 HTTP Strict-Transport-Security (HSTS) support request for the oauth-server
- Deferred