Configure the security policies and HTTP response headers

Sitefinity CMS comes with a set of predefined security policies. The Web security module reads the configuration for each security policy and sets the value of the corresponding HTTP response headers. You can configure the security policies separately and you can turn them on and off separately.

To configure the security headers, perform the following:

  1. In Sitefinity CMS backend, navigate to Administration » Settings
    The Basic Settings page appears.
  2. In the left-hand side navigation, click on WebSecurity 
    A list of the predefined security policies appear. Each policy controls a HTTP header listed in the HTTP header column.
  3. Click Edit for the security policy that you want to configure
    The security policy edit dialog appears
  4. Edit the properties of the security policy. Each property value, exposed for editing in the security policy edit dialog, translates to a value of the HTTP response headers. For more information about the headers, see Predefined security headers in HTTP response. You can also uncheck/check the Enable [security policy name] checkbox to disable/enable the security policy.
  5. NOTE: There are headers that support reporting. If you want to turn on the Content-Security-Policy-Report-Only or the Public-Key-Pins -Report-Only headers, you must disable the Content-Security-Policy and the Public-Key-Pins headers, respectively.
    For more information, see Configure reporting.
  6. Click Done to save your changes.

Globally disable sending all security HTTP response headers

You can globally disable all security headers, by navigation to Administration » Settings » Advanced » WebSecurity » HttpSecurityHeaders and selecting Disable sending security headers in the http response checkbox. We do not recommend using this option.

Was this article helpful?