laptop and a wrench

Bug

The HTTP Strict Transport Security (HSTS) header is not present on 302 (redirect) responses for Portal for ArcGIS.

Portal for ArcGIS
Bug ID Number BUG-000158917
SubmittedJune 7, 2023
Last ModifiedDecember 11, 2024
Applies toPortal for ArcGIS
Version found10.9.1
Operating SystemWindows Server
Operating System Version2016 64 Bit
Version Fixed11.2
StatusFixed

Workaround

There is not currently a workaround to fix this. However, the HSTS header is present on the internal Portal for ArcGIS site if HSTS is configured in the settings. There is only an issue when security scanners run the scan on https://fqdn:7443, and it presumes HSTS is not enabled. This is because the URL redirects to Portal for ArcGIS Home, and the redirect itself does not have the HSTS header present.

Steps to Reproduce

Bug ID: BUG-000158917

Software:

  • Portal for ArcGIS

Get notified when the status of a bug changes

Download the Esri Support App

Discover more on this topic

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options