laptop and a wrench

Bug

The HTTP Strict Transport Security (HSTS) header is not present on 302 (redirect) responses for Portal for ArcGIS.

Portal for ArcGIS
Bug-ID-Nummer BUG-000158917
EingereichtJune 7, 2023
Zuletzt geändertDecember 11, 2024
Gilt fürPortal for ArcGIS
Gefunden in Version10.9.1
BetriebssystemWindows Server
Betriebssystemversion2016 64 Bit
Behoben in Version11.2
StatusFixed

Workaround

There is not currently a workaround to fix this. However, the HSTS header is present on the internal Portal for ArcGIS site if HSTS is configured in the settings. There is only an issue when security scanners run the scan on https://fqdn:7443, and it presumes HSTS is not enabled. This is because the URL redirects to Portal for ArcGIS Home, and the redirect itself does not have the HSTS header present.

Schritte zur Reproduzierung

Bug-ID: BUG-000158917

Software:

  • Portal for ArcGIS

Benachrichtigung erhalten, wenn sich der Status eines Bugs ändert

Esri Support App herunterladen

Weitere Informationen zu diesem Thema erkunden

Unterstützung durch ArcGIS-Experten anfordern

An den technischen Support wenden

Esri Support App herunterladen

Zu Download-Optionen wechseln