[ https://issues.apache.org/jira/browse/OOZIE-3312?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Julia Kinga Marton updated OOZIE-3312: -------------------------------------- Attachment: OOZIE-3312-004.patch > Add support for HSTS > --------------------- > > Key: OOZIE-3312 > URL: https://issues.apache.org/jira/browse/OOZIE-3312 > Project: Oozie > Issue Type: Bug > Components: security > Reporter: Peter Cseh > Assignee: Julia Kinga Marton > Priority: Major > Attachments: OOZIE-3312-001.patch, OOZIE-3312-002.patch, > OOZIE-3312-003.patch, OOZIE-3312-004.patch > > > As a security best practice we should add support for HSTS via oozie-site.xml > in case of embedded Jetty. > [https://www.owasp.org/index.php/HTTP_Strict_Transport_Security_Cheat_Sheet] > [http://www.eclipse.org/jetty/documentation/9.3.x/embedded-examples.html] - > this page is not available anymore > [https://www.eclipse.org/jetty/documentation/9.4.15.v20190215/embedded-examples.html] > > Maybe we should even make it enabled by default when SSL is configured. -- This message was sent by Atlassian JIRA (v7.6.3#76005)