Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-34970

foreman-proxy lacks HSTS support

XMLWordPrintable

    • 5
    • False
    • foreman-proxy-3.14.0.1
    • Important
    • sat-endeavour
    • None
    • None
    • None
    • To Do

      Problem Statement

      Enable HTTP Strict Transport Security (HSTS) on the foreman-proxy daemon in Red Hat Satellite. Currently, security scanners flag it as non-compliant, creating issues with security exceptions. Enabling HSTS will improve compliance and reduce the need for variances, enhancing user experience in enterprise environments.

      User Experience & Workflow

      End-State: Foreman-proxy enforces HSTS, resolving compliance issues.

      Requirements

      A setting to enable HSTS on the foreman-proxy daemon

      Business Impact

      Without HSTS, security scanners will continue to flag non-compliance, complicating security exception processes and impacting enterprise security posture and efficiency.

              ekohlvan@redhat.com Ewoud Kohl van Wijngaarden
              rhn-support-cacortes Camila Cortes (Inactive)
              Lukas Pramuk Lukas Pramuk
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: