# Added HTTP Security Headers in Kibana Config \*.yml File, but it's not reflection in the server please help me

**URL:** <https://discuss.elastic.co/t/added-http-security-headers-in-kibana-config-yml-file-but-its-not-reflection-in-the-server-please-help-me/165228>\
**Category:** Kibana\
**Created:** [January 22, 2019, 12:38pm UTC](https://discuss.elastic.co/t/added-http-security-headers-in-kibana-config-yml-file-but-its-not-reflection-in-the-server-please-help-me/165228 "2019-01-22T12:38:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![balaskb](https://avatars.discourse-cdn.com/v4/letter/b/e9bcb4/32.png) [@balaskb](https://discuss.elastic.co/u/balaskb)\
**Post date:** [January 22, 2019, 12:38pm UTC](https://discuss.elastic.co/t/added-http-security-headers-in-kibana-config-yml-file-but-its-not-reflection-in-the-server-please-help-me/165228/1 "2019-01-22T12:38:48Z")

</div>

server.customResponseHeaders: { "Strict-Transport-Security" : "max-age= 31536000; includeSubdomains"}  
server.customResponseHeaders: { "X-Content-Type-Options": "nosniff"}  
server.customResponseHeaders: { "X-XSS-Protection": "1; mode=block"}  
server.customResponseHeaders: { "X-Frame-Options": "allow-from domainurl"}  
server.customResponseHeaders: { "Cache-Control" : "no-cache"}

---

<div class="post-metadata">

**Author:** ![stiltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stiltz/32/39714_2.png) [@stiltz](https://discuss.elastic.co/u/stiltz)\
**Post date:** [January 22, 2019, 3:54pm UTC](https://discuss.elastic.co/t/added-http-security-headers-in-kibana-config-yml-file-but-its-not-reflection-in-the-server-please-help-me/165228/2 "2019-01-22T15:54:56Z")

</div>

I'm not sure Kibana supports this natively - someone may know better on this. I have done this before by putting Kibana behind an nginx reverse proxy and defining my security headers in the nginx.conf.

DigitalOcean provides some fairly straightforward guides on setting up nginx as a reverse proxy for Kibana. You could simply leave out the authentication piece if you aren't looking for authentication (especially if you are already using Security). Here is a guide for Ubuntu 18.04: [https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-18-04](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-18-04)

Here is an example security header configuration in nginx: [https://gist.github.com/plentz/6737338](https://gist.github.com/plentz/6737338) This is billed as "The Best" configuration but I would pick and choose what I use based on my needs as there is plenty I wouldn't use from that configuration.

---

<div class="post-metadata">

**Author:** ![balaskb](https://avatars.discourse-cdn.com/v4/letter/b/e9bcb4/32.png) [@balaskb](https://discuss.elastic.co/u/balaskb)\
**Post date:** [January 25, 2019, 10:21am UTC](https://discuss.elastic.co/t/added-http-security-headers-in-kibana-config-yml-file-but-its-not-reflection-in-the-server-please-help-me/165228/3 "2019-01-25T10:21:56Z")

</div>

Thanks for the Update. But we need to do the setting via kibana yml file. Any help will be much appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2019, 10:26am UTC](https://discuss.elastic.co/t/added-http-security-headers-in-kibana-config-yml-file-but-its-not-reflection-in-the-server-please-help-me/165228/4 "2019-02-22T10:26:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
