-
Feature Request
-
Resolution: Done
-
Major
-
None
-
openshift-4.11, openshift-4.12, openshift-4.13, openshift-4.14, 4.13
-
False
-
None
-
False
-
Not Selected
-
-
-
-
- Proposed title of this feature request
Increase Openshift Webconsole security with CSP and HSTS headers
2. What is the nature and description of the request?
In order to mitigate certain attack vectors Openshfit Webconsole should have Content Security Policy and HTTP Strict-Transport-Security headers.
3. Why does the customer need this? (List the business requirements here)
We should clear internal security policies
4. List any affected packages or components
Openshift Container Platform
- is blocked by
-
RFE-3877 Configure operator managed route to enable HSTS annotation
- Accepted