Enterprise Secure Mobile Access - How to enable HTTP Strict Transport Security (HSTS)

Description

HTTP Strict Transport Security (HSTS) is a security enhancement that is specified by a web application through the use of a special response header. Once a supported browser receives this header, the browser will prevent any communications from being sent over HTTP to the specified domain and will instead send all communications over HTTPS. It also prevents HTTPS click through prompts on browsers.

This KB article describes how to enable this option using a Configuration Extension Mechanism (CEM) of the AMC.

Note:

  • HTTP Strict Transport Security (HSTS) is support from 11.4.0 onwards
  • HTTP Strict Transport Security (HSTS) is disabled by default
  • Once HSTS is enabled, users cannot override certificate errors or warnings if a self-signed certificate is used for the portal or if there is a host name mismatch.

Resolution

  1. Login to AMC as administrator
  2. Navigate to the System Configuration > Maintenance page.
  3. While on this page, change the URL to https://[AMC-IP-ADDRESS:8443/systemMaintenance.do?advanced=1 and press enter
  4. Click on Configure under Advanced > Configuration extensions
    Image
  5. On the Configuration Extensions page, click on New
  6. Under Key, enter EW_ENABLE_HSTS and set Value to true
  7. Click on OK
    Image
  8. Click on Save at the bottom
  9. Click on Pending Changes and apply the changes.
    Image

Related Articles

  • SMA100 End of Support No-Charge Replacement FAQ
    Read More
  • SMA1000: Post upgrade to 12.5.0 on AWS and Azure, we show the error Could not retrieve the DNS settings once we log in to AMC/CMS console
    Read More
  • Firmware version required to upgrade to version 12.5.0.
    Read More
not finding your answers?