We’ve recently updated our enabling Transport Layer Security (TLS) documentation (see References section below) to include guidelines for deploying HTTP Strict Transport Security (HSTS) with Oracle E-Business Suite Releases 12.2 and 12.1. HSTS allows you to specify a time period during which all browser communication must only use HTTPS. Using HSTS with Oracle E-Business Suite is an optional configuration.
If you plan to configure HSTS for Oracle E-Business Suite Release 12.2 or 12.1, we recommend the following practices:
- Configure HSTS at the TLS termination point (for example at the Oracle HTTP Server (OHS) or the load balancer).
- Either use the default HTTPS port (443), or specify the HTTPS port in all URLs.
- Begin by testing HSTS with a short time period.
- Enabling TLS in Oracle E-Business Suite Release 12.2 (MOS Note 1367293.1)
- Enabling TLS in Oracle E-Business Suite Release 12.1 (MOS Note 376700.1)
- FAQ: Oracle E-Business Suite Security (MOS Note 2063486.1)
Related Articles
