Question
How to enable Content-Security-Policy and Permissions-Policy Apache headers for all websites?
Answer
You may want to enable the Content-Security-Policy and Permissions-Policy headers to increase site security. This article provides the procedure to add these headers to the Apache configuration.
Note: The following instructions assume you already enabled HSTS on the server.
- Log into WHM as the
rootuser. - Navigate to WHM / Service Configuration / Apache Configuration
- Use the Include Editor
- Under the Pre-Main Include section, select "All Versions" from the drop-down menu.
-
Add the following entries:
CONFIG_TEXT: <If "%{HTTP_HOST} !~ /^(webmail|cpanel|whm)\./i">
Header always set Content-Security-Policy "default-src 'self'; font-src *;img-src * data:; script-src *; style-src *;"
Header always set Permissions-Policy "geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()"
</If> - Click the Update button, then the Restart Apache button to apply the configuration.
Comments
0 comments
Article is closed for comments.