Security headers missing and HTTPS not enforced on Dynamic Media custom domains in Adobe Experience Manager

Security assessments flag AEM Dynamic Media custom domains for missing security headers and for allowing HTTP access. This article describes how these headers are implemented and how HTTP traffic is redirected to HTTPS to secure Dynamic Media endpoints.

Description description

Environment

  • Product: Adobe Experience Manager Dynamic Media/Scene7
  • Instance: Production

Issue/Symptoms

The following issues occur on Dynamic Media custom domains:

  • The Content-Security-Policy header is missing from HTTP responses.
  • The X-Content-Type-Options header is missing.
  • The HTTP Strict Transport Security (HSTS) header is not enabled or configured.
  • HTTP requests are not redirected to HTTPS, allowing insecure access.

Resolution resolution

To fix this issue, follow these steps:

  1. Review the current response headers for your Dynamic Media custom domains by sending a request to an image URL over HTTP and HTTPS.

  2. Confirm that the following headers are present in the response:

    • Content-Security-Policy
    • X-Content-Type-Options
    • Strict-Transport-Security (HSTS)
  3. Ensure that any HTTP request receives a 301 redirect to the equivalent HTTPS URL.

  4. If any headers are missing or HTTP requests are not redirected, contact Adobe Support with your Dynamic Media account name and the affected domain details.

  5. After Adobe Engineering updates the configuration, repeat step 1 to verify that all required security headers are present and all traffic is enforced over HTTPS.

Notes: The implementation of these security controls requires coordination with Adobe Support and Engineering teams. Custom domain configurations vary depending on the account setup.

recommendation-more-help
experience-cloud-kcs-help-kbarticles