HSTS configuration not working in confluence 8.0.2

XMLWordPrintable

    • 2
    • Severity 2 - Major
    • 1

      Issue Summary

      This is reproducible on Data Center: Yes

      Steps to Reproduce

      1. Configure confluence on SSL
      2. Follow KB - how-to-enable-and-configure-http-strict-transport-security-hsts-response-header-on-confluence
      3. Attached web.xml with modifications

      Expected Results

      • Need to see strict transport security header, when accessing the instance

      Actual Results

      Headers not visible

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

      Important note for the fix

      Please read the updated documentation for configuring HSTS response headers.

      https://confluence.atlassian.com/confkb/how-to-enable-and-configure-http-strict-transport-security-hsts-response-header-on-confluence-1071813084.html

        1. web.xml
          173 kB

            Assignee:
            Richard Lau
            Reporter:
            Jetendra Ivaturi (Inactive)
            Votes:
            2 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: