# Security Header

**URL:** <https://discuss.elastic.co/t/security-header/247167>\
**Category:** Elasticsearch\
**Created:** [September 2, 2020, 4:57am UTC](https://discuss.elastic.co/t/security-header/247167 "2020-09-02T04:57:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![champes](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@champes](https://discuss.elastic.co/u/champes)\
**Post date:** [September 2, 2020, 4:57am UTC](https://discuss.elastic.co/t/security-header/247167/1 "2020-09-02T04:57:09Z")

</div>

Any thoughts on how to configure the following HTTP secure headers:

1. X-Frame-Options: deny
2. X-XSS-Protection: 1; mode=block
3. X-Content-Type-Options: nosniff
4. Strict-Transport-Security: max-age=31536000 ; includeSubDomains

versions that I'm using:  
elasticsearch-7.9.0-1.x86\_64  
kibana-7.9.0-1.x86\_64  
logstash-7.8.0-1.noarch  
metricbeat-7.9.0-1.x86\_64  
filebeat-7.9.0-1.x86\_64

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 2, 2020, 5:03am UTC](https://discuss.elastic.co/t/security-header/247167/2 "2020-09-02T05:03:03Z")

</div>

Welcome to our community! 😃

Can you elaborate where you want to enable them?

---

<div class="post-metadata">

**Author:** ![champes](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@champes](https://discuss.elastic.co/u/champes)\
**Post date:** [September 2, 2020, 5:25am UTC](https://discuss.elastic.co/t/security-header/247167/3 "2020-09-02T05:25:45Z")

</div>

Thanks Mark.

Basically this is for web-hardening, can these be added in Kibana.yml? It's just that I don't know how.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 2, 2020, 5:27am UTC](https://discuss.elastic.co/t/security-header/247167/4 "2020-09-02T05:27:12Z")

</div>

Right but it's not clear where you want these added. External only? Everywhere? Just between products in the stack? Something else?

---

<div class="post-metadata">

**Author:** ![champes](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@champes](https://discuss.elastic.co/u/champes)\
**Post date:** [September 2, 2020, 5:35am UTC](https://discuss.elastic.co/t/security-header/247167/5 "2020-09-02T05:35:15Z")

</div>

This Kibana should be only reachable within our network.

This Kibana service is located in one server only.

---

<div class="post-metadata">

**Author:** ![champes](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@champes](https://discuss.elastic.co/u/champes)\
**Post date:** [September 3, 2020, 3:07am UTC](https://discuss.elastic.co/t/security-header/247167/6 "2020-09-03T03:07:08Z")

</div>

Any thoughts on this please? thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 3, 2020, 3:11am UTC](https://discuss.elastic.co/t/security-header/247167/7 "2020-09-03T03:11:56Z")

</div>

I'm not clear on why access control and a firewall would not work?

---

<div class="post-metadata">

**Author:** ![champes](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@champes](https://discuss.elastic.co/u/champes)\
**Post date:** [September 3, 2020, 3:48am UTC](https://discuss.elastic.co/t/security-header/247167/8 "2020-09-03T03:48:21Z")

</div>

Our client wants more security. Here's what they told us

_For your reference as well, SSL is not enough to secure a web application. Coming from our past previous experience the common entry of our attacks is because of this weak security configuration. when I say this. Those are the enabled SSL sites we have but have no secure headers. This has been our standard in our security._

_Example:_  
_Strict-Transport-Security_  
_When a site performs a 301 redirect from the http to the https version of a site, the redirect does not fully protect the site visitor, since it can be intercepted between when the visitor requests the http version of the site. This web server is already vulnerable to a man in the middle attacks. By having this the attacker can have a lot of opportunity to stage further advance attacks that may lead to information disclosure._

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2020, 3:48am UTC](https://discuss.elastic.co/t/security-header/247167/9 "2020-10-01T03:48:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
