We’ve recently updated our enabling Transport Layer Security (TLS) documentation (see References section below) to include guidelines for deploying HTTP Strict Transport Security (HSTS) with Oracle E-Business Suite Releases 12.2 and 12.1. HSTS allows you to specify a time period during which all browser communication must only use HTTPS. Using HSTS with Oracle E-Business Suite is an optional configuration. 

If you plan to configure HSTS for Oracle E-Business Suite Release 12.2 or 12.1, we recommend the following practices:

  • Configure HSTS at the TLS termination point (for example at the Oracle HTTP Server (OHS) or the load balancer).
  • Either use the default HTTPS port (443), or specify the HTTPS port in all URLs.
  • Begin by testing HSTS with a short time period.
References

Related Articles