Some security teams will mandate that you set HTTP Security Headers in Responses.
This article will discuss setting them in Siteminder Access Gateway.
Release : Any
Component : Siteminder Access Gateway
HTTP Security Headers are not enabled by default and are considered optional.
1) Logon to the Siteminder Access Gateway Host
2) Open the 'httpd.conf' file
3) Make sure that the 'mod_headers' is being loaded
LoadModule headers_module modules/
4) Set one or more of the following HTTP Headers in the following 'IfModule' directive:
<IfModule mod_headers.c>
Header set X-Frame-Options "SAMEORIGIN"
Header set X-XSS-Protection "1; mode=block"
Header set X-Content-Type-Options "nosniff"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
NOTE: Your security team may dictate 'max-age' value for the 'Strict-Transport-Security' directive.
5) Restart the Access Gateway server using systemctl
This will set these headers for all virtual servers, for both HTTP and HTTPS requests.