Bug ID 826625: FPS does not respect HTTP profile's HSTS configuration

Last Modified: Dec 13, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP FPS(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.4, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 15.0.0, 15.0.1, 15.1.0

Opened: Sep 15, 2019
Severity: 3-Major

Symptoms

FPS plugin does not respect Strict-Transport-Security configuration and as a result, responses for FPS self URLs does not contain the Strict-Transport-Security header

Impact

FPS responses do not include the Strict-Transport-Security header.

Conditions

-- Virtual server has a http profile where 'HTTP Strict Transport Security' mode is enabled. -- Virtual server has a FPS profile attached.

Workaround

Use iRules according to your configuration/requirements: HTTP::header insert Strict-Transport-Security ...

Fix Information

None

Behavior Change