# Csp configuration

**URL:** <https://discuss.elastic.co/t/csp-configuration/200052>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 18, 2019, 4:07pm UTC](https://discuss.elastic.co/t/csp-configuration/200052 "2019-09-18T16:07:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashu1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashu1/32/75042_2.png) [@ashu1](https://discuss.elastic.co/u/ashu1)\
**Post date:** [September 18, 2019, 4:07pm UTC](https://discuss.elastic.co/t/csp-configuration/200052/1 "2019-09-18T16:07:42Z")

</div>

Hi all...I was asked to do App scan on Kibana and on doing the scan,the generated reports listed out below issues.

1. [http://hostname:5601/app/kibana](http://hostname:5601/app/kibana) and [http://hostname:5601/ui/favicons/manifest.json](http://hostname:5601/ui/favicons/manifest.json) and  
[http://hostname:5601/bundles/app/kibana/bootstrap.js](http://hostname:5601/bundles/app/kibana/bootstrap.js)

Issue: Insecure web application programming or configuration  
FIX: Configure "Content-Security-Policy" header with secure policies  
Configure "X-Content-Type-Options" header with "nosniff" value  
Config your server to use the "X-XSS-Protection" header with value '1'

I've tried setting csp policy and but it didn't fix the issues.Any suggestions on this??

Thanks

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [September 18, 2019, 4:11pm UTC](https://discuss.elastic.co/t/csp-configuration/200052/2 "2019-09-18T16:11:17Z")

</div>

Hi @ashu1,

You can configure Kibana to send custom response headers by specifying `server.customResponseReaders` in your `kibana.yml` (example here: [Format of kibana server.customResponseHeaders](https://discuss.elastic.co/t/format-of-kibana-server-customresponseheaders/108000))

---

<div class="post-metadata">

**Author:** ![ashu1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashu1/32/75042_2.png) [@ashu1](https://discuss.elastic.co/u/ashu1)\
**Post date:** [September 18, 2019, 4:22pm UTC](https://discuss.elastic.co/t/csp-configuration/200052/3 "2019-09-18T16:22:16Z")

</div>

@Larry_Gregory --Thanks,let me configure and run the scan.

---

<div class="post-metadata">

**Author:** ![ashu1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashu1/32/75042_2.png) [@ashu1](https://discuss.elastic.co/u/ashu1)\
**Post date:** [September 18, 2019, 10:39pm UTC](https://discuss.elastic.co/t/csp-configuration/200052/4 "2019-09-18T22:39:18Z")

</div>

@Larry_Gregory -- 2 out of 3 issues are fixed.  
When I tried to set "Content-Security-Policy" header kibana fails to load.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [September 19, 2019, 12:26pm UTC](https://discuss.elastic.co/t/csp-configuration/200052/5 "2019-09-19T12:26:22Z")

</div>

Kibana ships with its own set of CSP rules, which it should be sending to the browser on its own already.

The built-in CSP is still pretty unrestrictive, so it is possible that an automated security scanner is still finding issues with the policy that's in place. We are actively working on locking down the policy further, but this takes time, as Kibana uses a lot of libraries that themselves rely on permissive CSP policies.

---

<div class="post-metadata">

**Author:** ![ashu1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashu1/32/75042_2.png) [@ashu1](https://discuss.elastic.co/u/ashu1)\
**Post date:** [September 20, 2019, 7:14am UTC](https://discuss.elastic.co/t/csp-configuration/200052/6 "2019-09-20T07:14:55Z")

</div>

@Larry_Gregory -- Thanks a lot!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2019, 7:27am UTC](https://discuss.elastic.co/t/csp-configuration/200052/7 "2019-10-18T07:27:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
