we are looking to disable HTTP Options on our cluster activegate, per request from our security team as it has raised concerns about potential vulnerabilities. Is there any way that those options can be disabled?
Thanks in advance
Solved! Go to Solution.
Hello @Andrew E.
You can use ActiveGate properties for the configuration. These properties are applicable for both Environment ActiveGates and Cluster ActiveGates.
Have a look on the below link for more insight.
HTTP OPTIONS is necessary for REST API and Real user monitoring (beacon forwarders). The server does not respond with sensitive information, thus
is not considered a security vulnerability.
HTTPS OPTIONS method is also a requirement for CORS