21 Aug 2020
	
		
		01:38 PM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 - last edited on 
    
	
		
		
		13 Mar 2025
	
		
		11:52 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 by 
				
		 MaciejNeumann
		
			MaciejNeumann
		
		
		
		
		
		
		
		
	
			
		
Hi,
The security team at one of my customers has said that the HSTS-header is not placed on the following URL's:
- https://XXXXX.dynatrace-managed.com/beacon/ 
- https://XXXXX.dynatrace-managed.com/bf/ 
- https://XXXXX.dynatrace-managed.com/ruxitagentjs_2bnr_0.js 
- https://XXXXX.dynatrace-managed.com/v2 
Is this a known issue? Can we expect the HSTS-Header to not be placed on these URL's, or should they also be placed on those URL's?
Thanks in advance!
Regards,
Sten
Solved! Go to Solution.
21 Aug 2020 07:13 PM
First three endpoints are ActiveGate component endpoints are the excluded from hsts. The last one is part of REST API path and there’s no resource in that specific path anyway.
If you have more sensitive questions, open a support case.
