- Community Home
- >
- Software
- >
- HPE OneView
- >
- OneView 5.30.00_ HSTS
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2021 11:10 PM
02-10-2021 11:10 PM
OneView 5.30.00_ HSTS
Hi,
Right now there is no HSTS in OneView 5.30.00. It should be there as defined by RFC 6797.
https://tools.ietf.org/html/rfc6797
How should the HSTS be activated?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2021 09:56 AM
02-11-2021 09:56 AM
Re: OneView 5.30.00_ HSTS
You need to update to HPE OneView 5.50.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-12-2021 12:15 AM
02-12-2021 12:15 AM
Re: OneView 5.30.00_ HSTS
HI,
How should the HSTS be activated in the OneView 5.50?
Or is HSTS activated by default on this release?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2021 08:26 AM
07-08-2021 08:26 AM
Re: OneView 5.30.00_ HSTS
Is HSTS supported on Oneview 6.1? My Teneble security scanner says it is not enabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2021 08:56 AM
07-08-2021 08:56 AM
Re: OneView 5.30.00_ HSTS
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2021 08:59 AM
07-08-2021 08:59 AM
Re: OneView 5.30.00_ HSTS
I have updated to Oneview 6.1 and am receiving this alert from my Tenable scanner:
142960 HSTS Missing From HTTPS Server (RFC
6797) Medium 1 Web Servers
Description: The remote web server is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured
on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle
attacks, and weakens cookie-hijacking protections.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2021 09:00 AM
07-08-2021 09:00 AM
Re: OneView 5.30.00_ HSTS
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-12-2021 07:29 AM
07-12-2021 07:29 AM
Re: OneView 5.30.00_ HSTS
We are experiencing the same issue with our security scans. I had a case open with HPE and they said to update to 5.5 or higher. We updated to 6.1 and the vulnerability still shows on the secruity scans. I have been following this thread to see if there was a fix.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-13-2021 11:30 AM
07-13-2021 11:30 AM
Re: OneView 5.30.00_ HSTS
We have identified a regression within OneView 6.00 through 6.20 that is causing this. Starting with 6.00, we changed the OneView update internal mechanism to an image based approach to updating, in order to achieve faster updates. Unfortunately, one of the internal config files that enabled HSTS support is not being captured. So any customer updating to 6.00, 6.10 or the recently released 6.20 update will experience this regression. We are working on a fix, and will be in a future OneView update that will re-enable HSTS support automatically.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2021 11:03 AM
07-26-2021 11:03 AM
Re: OneView 5.30.00_ HSTS
Thanks Chris for the reply. I notified my secruity team to let them know. Will be following this thread for updates.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2021 02:19 PM
12-08-2021 02:19 PM
Re: OneView 5.30.00_ HSTS
Wanted to follow up on this. Has the HSTS issue been fixed in the latest version of oneview, 6.3 and/or 6.4 ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2021 03:12 PM
12-08-2021 03:12 PM
Re: OneView 5.30.00_ HSTS
Yes, this was addressed in OneView 6.30.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
