Does EDR support HSTS
search cancel

Does EDR support HSTS

book

Article ID: 219707

calendar_today

Updated On:

Products

Endpoint Detection and Response

Issue/Introduction

Running a vulnerability scan against the Symantec Endpoint Detection and Response (SEDR) appliance it is noted that HSTS is not available.

Resolution

SEDR returns 404 against HTTP requests and does not redirect to HTTPS.  Because of this there is no opportunity to hijack HTTPS protocol which HSTS supposes to protect.  As such HSTS is not supported for the EDR appliance and is therefore not enabled.