As of 6.4.1.24, UW supports
HSTS
HSTS can be enabled/disabled via the Login Policy used by the UW relays.
- Open webAdmin.
- Expand Tree Root.
- Expand the Stoneware OU folder.
- Select the DefaultLoginPolicy object.
- Check the HSTS Enable checkbox on the Properties tab.
- Click SAVE.
- Restart the webNetwork Service on all of the relay servers.
With the introduction of 7.0.0.63, UW supports the ability to add custom
Security Headers. The HSTS checkbox has been removed, in favor of just adding the Strict-Transport-Security header.
**IMPORTANT NOTE**
When enabling HSTS you must be using a real SSL certificate for the 8090 Management Console of your servers.
You will find a wizard in the 8090 Managemt Console that will grab the SSL Certificate from the primary keystore, for use by the 8090 Management Console. This must be done prior to enabling HSTS.
This article does not apply if offloading SSL. HSTS would be handled by the SSL device.