14.14 Disabling HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS) is a web security policy mechanism. By default, HSTS is now enabled to protect web application users against some passive (eavesdropping) and active network attacks.

To disable HSTS, perform the following steps:

  1. Go to %ZENSERVER_HOME%\bin (example: C:\Program Files (x86)\Micro Focus\ZENworks\bin).

  2. Open the ZENServerW file.

  3. In the Java tab, add the -DEnableHSTS=false at the end of the Java Options section as a new line.

    By default, -DEnableHSTS= is set to true.

On a Linux Primary Server:

  1. Open the /etc/opt/microfocus/zenworks/settings/zenserversettings.sh file.

  2. Set -DEnableHSTS property to false in the following line:


  3. By default, -DEnableHSTS= is set to true.

NOTE:ZENworks no longer supports Windows Server as a Primary Server from version 24.2 onwards. For more information, see End of Windows Primary Server Support.

In Tomcat:

  1. Open the <Tomcat>/conf/web.xml file from the following path:

    • On Linux Server: /opt/microfocus/zenworks/share/tomcat/conf/

    • On Windows Server: <ZENSERVER_HOME>\services\zenserver\conf\

  2. Comment the httpHeaderSecurity filter definition and the <filter-mapping> section.

  3. Save the file and restart Tomcat.