<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynatrace Managed Security Audit HTTP Response Header in Dynatrace Managed Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116073#M1381</link>
    <description>&lt;P&gt;Thanks for your thorough answer. This gives me enough information &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Aug 2020 11:21:44 GMT</pubDate>
    <dc:creator>ssmeets</dc:creator>
    <dc:date>2020-08-24T11:21:44Z</dc:date>
    <item>
      <title>Dynatrace Managed Security Audit HTTP Response Header</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116069#M1377</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;At one of my customers we're in the process of installing Dynatrace Managed. Security is doing an audit and they have found some information in the HTTP Response Header of the Dynatrace UI that shouldn't be there.&lt;/P&gt;&lt;P&gt;The information is as follows:&lt;/P&gt;&lt;P&gt;Server: nginx&lt;/P&gt;&lt;P&gt;Traffic-Source: CUSTOMER&lt;/P&gt;&lt;P&gt;Security says that information about what webserver Dynatrace Managed is running on, can be misused by certain individuals. They claim that this information shouldn't be there.&lt;BR /&gt;I need to give them an answer why this information is included in the HTTP Response header. &lt;/P&gt;&lt;P&gt;Also, they said that the Web.conf file was visible during one request when they tested the POC-environment over a year ago. Can someone guarantee that this should not be the case?&lt;/P&gt;&lt;P&gt;Can someone help me with this?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 12:14:44 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116069#M1377</guid>
      <dc:creator>ssmeets</dc:creator>
      <dc:date>2020-08-21T12:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace Managed Security Audit HTTP Response Header</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116070#M1378</link>
      <description>&lt;P&gt;information disclosure may be the case - if it is - we will make sure this to hidden. &lt;/P&gt;&lt;P&gt;For the web.conf I’d be very surprised. &lt;/P&gt;&lt;P&gt;Anyway, please open support case so we can track that individually.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 18:09:39 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116070#M1378</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2020-08-21T18:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace Managed Security Audit HTTP Response Header</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116071#M1379</link>
      <description>&lt;P&gt;While we are fixing this in the product, this might be a nginx setting that can be configured in the nginx configuration file.&lt;/P&gt;&lt;P&gt;For reconfiguring nginx settings in Dynatrace Managed, we offer a functionality which is described here: https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/configuration/configurable-properties-of-dynatrace-managed/&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 06:33:11 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116071#M1379</guid>
      <dc:creator>Michael_Plank</dc:creator>
      <dc:date>2020-08-24T06:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace Managed Security Audit HTTP Response Header</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116072#M1380</link>
      <description>&lt;P&gt;Thanks for your answer! Unfortunately, I can't give anymore information because this was feedback from a POC environment that they audited. I just wanted to make sure what Dynatrace's statements were on these points. &lt;BR /&gt;&lt;BR /&gt;If I receive any feedback from Security on the new environment, I'll open a support ticket to discuss these points further &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 11:12:55 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116072#M1380</guid>
      <dc:creator>ssmeets</dc:creator>
      <dc:date>2020-08-24T11:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace Managed Security Audit HTTP Response Header</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116073#M1381</link>
      <description>&lt;P&gt;Thanks for your thorough answer. This gives me enough information &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 11:21:44 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Dynatrace-Managed-Security-Audit-HTTP-Response-Header/m-p/116073#M1381</guid>
      <dc:creator>ssmeets</dc:creator>
      <dc:date>2020-08-24T11:21:44Z</dc:date>
    </item>
  </channel>
</rss>

