IBM Support

LI81628: ADD MORE SECURITY HEADERS TO PORTS 443 AND 4443

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • portal-www/web nginx server default page should container
    security related headers
    

Local fix

  • Port 4443 should not be accessible to anyone except for the
    other cluster members. The only port on the OVA's that should
    be accessible from anything other than another OVA is port
    443.
    
    Clients should not be exposing anything other than 443 to
    external.
    4443 is needed for communication between cluster
    members
    

Problem summary

  • For Developer Portal, portal-www/web nginx server default page
    should be updated to add additional headers
    

Problem conclusion

  • In 2018.4.1.13, these headers are added:
    
    Strict-Transport-Security: max-age=31536000; includeSubDomains
     X-Frame-Options: DENY
     X-XSS-Protection: 1;mode=block
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI81628

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    18X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-07-20

  • Closed date

    2020-09-13

  • Last modified date

    2020-09-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18X","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
14 January 2022