Forum Discussion
crodriguez
Jul 09, 2018Ret. Employee
How about something like below? This solution checks to make sure the server is not already sending one before inserting the default.
when HTTP_RESPONSE {
If server has not sent an HSTS header, BIG-IP will
if { !([HTTP::header exists "Strict-Transport-Security"]) } {
HTTP::header insert "Strict-Transport-Security" "max-age=63072000"
}
}