# HTTP strict Transport Security

**URL:** <https://discuss.elastic.co/t/http-strict-transport-security/172591>\
**Category:** Kibana\
**Created:** [March 15, 2019, 6:03pm UTC](https://discuss.elastic.co/t/http-strict-transport-security/172591 "2019-03-15T18:03:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mbarker](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@mbarker](https://discuss.elastic.co/u/mbarker)\
**Post date:** [March 15, 2019, 6:03pm UTC](https://discuss.elastic.co/t/http-strict-transport-security/172591/1 "2019-03-15T18:03:02Z")

</div>

We recently had a Burp Suite scan done and it found that "BurpSuite Found: 'Strict transport security not enforced' (Type: 16777984)"  
To correct the issue, below is what was suggested:-

"The application should instruct web browsers to only access the application using HTTPS. To do this, enable HTTP Strict Transport Security (HSTS) by adding a response header with the name 'Strict-Transport-Security' and the value 'max-age=expireTime', where expireTime is the time in seconds that browsers should remember that the site should only be accessed using HTTPS. Consider adding the 'includeSubDomains' flag if appropriate."

How do I make those changes in Kibana?

Thanks

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 22, 2019, 11:44am UTC](https://discuss.elastic.co/t/http-strict-transport-security/172591/2 "2019-03-22T11:44:18Z")

</div>

Hello,  
You can try and achieve this by using the `server.customResponseHeaders` [https://www.elastic.co/guide/en/kibana/current/settings.html](https://www.elastic.co/guide/en/kibana/current/settings.html) and specifying your own custom one.  
The format for the setting is like this: [Format of kibana server.customResponseHeaders](https://discuss.elastic.co/t/format-of-kibana-server-customresponseheaders/108000)

---

<div class="post-metadata">

**Author:** ![mbarker](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@mbarker](https://discuss.elastic.co/u/mbarker)\
**Post date:** [March 27, 2019, 4:10pm UTC](https://discuss.elastic.co/t/http-strict-transport-security/172591/3 "2019-03-27T16:10:10Z")

</div>

Thanks, setting the server.customResponseHeaders did work. Is there a similar for Elasticsearch?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2019, 4:16pm UTC](https://discuss.elastic.co/t/http-strict-transport-security/172591/4 "2019-04-24T16:16:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
