<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Scoring an A+ In Securityheaders.io	</title>
	<atom:link href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/</link>
	<description>-={ The Nutanix and EUC GURU }=-</description>
	<lastBuildDate>Wed, 06 Jan 2021 15:16:33 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
	<item>
		<title>
		By: Mike		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-255</link>

		<dc:creator><![CDATA[Mike]]></dc:creator>
		<pubDate>Wed, 06 Jan 2021 15:16:33 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-255</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-254&quot;&gt;Mike&lt;/a&gt;.

This also could use an update in content to address similar reporting and header requirements in Bitsight since that&#039;s what alot of companies are using now to track this kind of thing....

i did manage to get it up to an A by binding to the global default and not the global override so FYI for anyone if they run into same thing.

That being said.  An A in Securityheaders.io doesn&#039;t help me if the same config shows as &quot;Fair&quot; in bitsight]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-254">Mike</a>.</p>
<p>This also could use an update in content to address similar reporting and header requirements in Bitsight since that&#8217;s what alot of companies are using now to track this kind of thing&#8230;.</p>
<p>i did manage to get it up to an A by binding to the global default and not the global override so FYI for anyone if they run into same thing.</p>
<p>That being said.  An A in Securityheaders.io doesn&#8217;t help me if the same config shows as &#8220;Fair&#8221; in bitsight</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Mike		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-254</link>

		<dc:creator><![CDATA[Mike]]></dc:creator>
		<pubDate>Mon, 04 Jan 2021 18:32:05 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-254</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-244&quot;&gt;Jeroen&lt;/a&gt;.

This aaa custom response link is broken.  can we post the content here?
I also notice that the content security policy doesn&#039;t work and when i use it as stated above, securityheaders.io shows it as not existing and gives me a B.  any ideas?]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-244">Jeroen</a>.</p>
<p>This aaa custom response link is broken.  can we post the content here?<br />
I also notice that the content security policy doesn&#8217;t work and when i use it as stated above, securityheaders.io shows it as not existing and gives me a B.  any ideas?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jeroen Tielen		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-253</link>

		<dc:creator><![CDATA[Jeroen Tielen]]></dc:creator>
		<pubDate>Wed, 27 Jun 2018 15:21:13 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-253</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-252&quot;&gt;Jason&lt;/a&gt;.

Well tell your CSO that all fortune 500 companies are using the netscaler. If this was/is a security breach then it was already patch/known by Citrix. But what you can do is open a case by Citrix and let them come back with a decent answer ;) ]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-252">Jason</a>.</p>
<p>Well tell your CSO that all fortune 500 companies are using the netscaler. If this was/is a security breach then it was already patch/known by Citrix. But what you can do is open a case by Citrix and let them come back with a decent answer 😉 </p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jason		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-252</link>

		<dc:creator><![CDATA[Jason]]></dc:creator>
		<pubDate>Wed, 27 Jun 2018 15:16:31 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-252</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-251&quot;&gt;Jeroen Tielen&lt;/a&gt;.

Apologies for the double comment. That&#039;s too bad. We&#039;re a payroll company and security is scrutinizing the unsafe-inline and unsafe-eval. 

Thanks]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-251">Jeroen Tielen</a>.</p>
<p>Apologies for the double comment. That&#8217;s too bad. We&#8217;re a payroll company and security is scrutinizing the unsafe-inline and unsafe-eval. </p>
<p>Thanks</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jeroen Tielen		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-251</link>

		<dc:creator><![CDATA[Jeroen Tielen]]></dc:creator>
		<pubDate>Wed, 27 Jun 2018 14:04:33 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-251</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-249&quot;&gt;Jason&lt;/a&gt;.

Correct ;)]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-249">Jason</a>.</p>
<p>Correct 😉</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jeroen Tielen		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-250</link>

		<dc:creator><![CDATA[Jeroen Tielen]]></dc:creator>
		<pubDate>Wed, 27 Jun 2018 14:04:00 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-250</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-248&quot;&gt;Jason&lt;/a&gt;.

Hi Jason, is you are happy with the A and not A+ then yes keep those in the CSP.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-248">Jason</a>.</p>
<p>Hi Jason, is you are happy with the A and not A+ then yes keep those in the CSP.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jason		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-249</link>

		<dc:creator><![CDATA[Jason]]></dc:creator>
		<pubDate>Thu, 21 Jun 2018 13:47:25 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-249</guid>

					<description><![CDATA[As long as Citrix implements “unsafe-inline” and “unsafe-eval” scripts in the Gateway we could not get it to work properly.

Does that mean the CSP MUST have both unsafe-inline and unsafe-eval due to NetScaler Gateway? It doesn&#039;t work without it? I can&#039;t see to get it to work if I remove those items.]]></description>
			<content:encoded><![CDATA[<p>As long as Citrix implements “unsafe-inline” and “unsafe-eval” scripts in the Gateway we could not get it to work properly.</p>
<p>Does that mean the CSP MUST have both unsafe-inline and unsafe-eval due to NetScaler Gateway? It doesn&#8217;t work without it? I can&#8217;t see to get it to work if I remove those items.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jason		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-248</link>

		<dc:creator><![CDATA[Jason]]></dc:creator>
		<pubDate>Wed, 20 Jun 2018 20:15:06 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-248</guid>

					<description><![CDATA[&quot;As long as Citrix implements “unsafe-inline” and “unsafe-eval” scripts in the Gateway we could not get it to work properly&quot;

Does this mean you must have “unsafe-inline” and “unsafe-eval” in your CSP? My Security group keeps bouncing back because it&#039;s failing scans. If I remove both values from my NetScaler CSP, the hosted site breaks. I run 11.0/71.22. Thanks.]]></description>
			<content:encoded><![CDATA[<p>&#8220;As long as Citrix implements “unsafe-inline” and “unsafe-eval” scripts in the Gateway we could not get it to work properly&#8221;</p>
<p>Does this mean you must have “unsafe-inline” and “unsafe-eval” in your CSP? My Security group keeps bouncing back because it&#8217;s failing scans. If I remove both values from my NetScaler CSP, the hosted site breaks. I run 11.0/71.22. Thanks.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jeroen		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-247</link>

		<dc:creator><![CDATA[Jeroen]]></dc:creator>
		<pubDate>Mon, 30 Apr 2018 12:49:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-247</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-246&quot;&gt;Bjron&lt;/a&gt;.

Look at the whole report. There should be pointers in there. ]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-246">Bjron</a>.</p>
<p>Look at the whole report. There should be pointers in there. </p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Bjron		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-246</link>

		<dc:creator><![CDATA[Bjron]]></dc:creator>
		<pubDate>Wed, 25 Apr 2018 10:05:30 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-246</guid>

					<description><![CDATA[Security Report Summary is showing &quot;R&quot; but all 6 headers are green. What might be the reason, its now showing A/A+?]]></description>
			<content:encoded><![CDATA[<p>Security Report Summary is showing &#8220;R&#8221; but all 6 headers are green. What might be the reason, its now showing A/A+?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Sebastiaan		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-245</link>

		<dc:creator><![CDATA[Sebastiaan]]></dc:creator>
		<pubDate>Thu, 15 Mar 2018 15:55:25 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-245</guid>

					<description><![CDATA[I&#039;m going to check out the blog post and try to bind them globally. Thanks.
Hopefully you figure it out quickly :) and you can enjoy your evening.

-Sebastiaan]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m going to check out the blog post and try to bind them globally. Thanks.<br />
Hopefully you figure it out quickly 🙂 and you can enjoy your evening.</p>
<p>-Sebastiaan</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jeroen		</title>
		<link>https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-244</link>

		<dc:creator><![CDATA[Jeroen]]></dc:creator>
		<pubDate>Thu, 15 Mar 2018 15:26:06 +0000</pubDate>
		<guid isPermaLink="false">https://www.jeroentielen.nl/?p=6490#comment-244</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-243&quot;&gt;Sebastiaan&lt;/a&gt;.

In this blog post you find some more information. As you can&#039;t bind the rewrite policies to an AAA vServer they will work if you bind them globally. Although they haven&#039;t tested this on newer versions of the NetScaler. Now you have triggered me ;) It&#039;s gonna be a long night hahahaha. I will try to reproduce this myself.

https://discussions.citrix.com/topic/366082-netscaler-aaa-page-response-with-custom-header/]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.jeroentielen.nl/scoring-an-a-in-securityheaders-io/#comment-243">Sebastiaan</a>.</p>
<p>In this blog post you find some more information. As you can&#8217;t bind the rewrite policies to an AAA vServer they will work if you bind them globally. Although they haven&#8217;t tested this on newer versions of the NetScaler. Now you have triggered me 😉 It&#8217;s gonna be a long night hahahaha. I will try to reproduce this myself.</p>
<p><a href="https://discussions.citrix.com/topic/366082-netscaler-aaa-page-response-with-custom-header/" rel="nofollow ugc">https://discussions.citrix.com/topic/366082-netscaler-aaa-page-response-with-custom-header/</a></p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
