Content Security Policy response header support for NetScaler Gateway and authentication virtual server-generated responses
-
The primary function of a CSP response header is to prevent CSS attacks.
-
In addition to restricting the domains from which content can be loaded, the server can specify which protocols are allowed to be used; for example (and ideally, from a security standpoint), a server can specify that all contents must be loaded using HTTPS.
-
CSP helps in securing NetScaler from cross-site scripting attacks by securing files like "tmindex.html" and "homepage.html. The file "tmindex.html" is related to authentication and the file "homepage.html" is related to the published apps/links.
Configuring Content-Security-Policy header for NetScaler Gateway and authentication virtual server-generated responses
-
By default, the CSP header is enabled in the following NetScaler builds:
-
14.1-47.46 and later
-
13.1-59.19 and later
-
-
While enabling or disabling the default CSP policy, you are recommended to run the following command.
Flush cache contentgroup loginstaticobjects -
For modifying the CSP for /logon/LogonPoint/index.html, modify the "Header set Content-Security-Policy" value as required under the section corresponding to the logon directory, which can be found under the directory
/var/netscaler/logon. -
For instructions on how to configure a rewrite action and policy using the GUI, see Rewrite.
set aaa parameter -defaultCSPHeader <ENABLE/DISABLE>
-
Navigate to NetScaler Gateway > Global Settings, click Change authentication AAA settings under Authentication Settings.CSP global-1
-
On the Configure AAA Parameters page, select the Enabled in Default CSP Header field.CSP global-2
Custom Content-Security-Policy header
https://company.fqdn.com, https://example.com.
add rewrite action modify_csp insert_http_header Content-Security-Policy "\"default-src 'self'; script-src 'self' https://company.fqdn.com 'unsafe-inline' 'unsafe-eval'; connect-src 'self'; img-src http://localhost:* https://example.com 'self' data: http: https:; style-src 'self' 'unsafe-inline'; font-src 'self'; frame-src 'self'; child-src 'self' com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://*; form-action 'self'; object-src 'self'; report-uri /nscsp_violation/report_uri\""
add rewrite policy csp_pol true modify_csp
bind authentication vserver auth_vs -policy csp_pol -priority 1 -type AAA_RESPONSE
bind authentication vserver auth_vs -policy csp_pol -priority 2 -type RESPONSE
-
If the packet engine generates the response, it is handled using
-type AAA_RESPONSE. -
If Apache generates the response, it is handled using
-type RESPONSE.
bind vpn vserver vpn_vs -policy csp_pol -priority 1 -type AAA_RESPONSE
bind vpn vserver vpn_vs -policy csp_pol -priority 2 -type RESPONSE
Rewrite policies to support DUO authentication
Rewrite policies for VPN virtual server
add rewrite action delete_csp_header delete_http_header Content-Security-Policy
add rewrite policy delete_csp_header_policy "HTTP.REQ.URL.CONTAINS(\"/logon/LogonPoint/tmindex.html\")" delete_csp_header
bind authentication vserver authvs_radius -policy delete_csp_header_policy -priority 1 -gotoPriorityExpression NEXT -type RESPONSE
add rewrite action modify_csp_header_with_duo insert_http_header Content-Security-Policy "\"default-src \'self\'; script-src https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://.duosecurity.com \'self\' \'unsafe-inline\'; connect-src \'self\'; img-src http://localhost: \'self\' data:; style-src \'self\' \'unsafe-inline\'; font-src \'self\' data:; frame-src https://www.google.com/recaptcha/ com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view://* nsgcepa://* application://* receiver:// https://.duosecurity.com \'self\'; child-src \'self\' com.citrix.agmacepa:// citrixng:// com.citrix.nsgclient://* vmware-view://* nsgcepa://nsgcepa application://*; form-action \'self\'; object-src \'none\'; report-uri /nscsp_violation/report_uri\""
add rewrite policy add_modified_csp_header_with_duo "HTTP.REQ.URL.CONTAINS(\"/logon/LogonPoint/tmindex.html\")" modify_csp_header_with_duo
bind authentication vserver authvs_radius -policy add_modified_csp_header_with_duo -priority 2 -gotoPriorityExpression NEXT -type RESPONSE
Rewrite policies for Traffic Management (TM) virtual server
add rewrite action delete_csp_header delete_http_header Content-Security-Policy
add rewrite policy delete_csp_header_policy "HTTP.REQ.URL.CONTAINS(\"/logon/LogonPoint/tmindex.html\")" delete_csp_header
bind authentication vserver tmvs_radius -policy delete_csp_header_policy -priority 1 -gotoPriorityExpression NEXT -type RESPONSE
add rewrite action modify_csp_header_with_duo insert_http_header Content-Security-Policy "\"default-src \'self\'; script-src https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://.duosecurity.com \'self\' \'unsafe-inline\'; connect-src \'self\'; img-src http://localhost: \'self\' data:; style-src \'self\' \'unsafe-inline\'; font-src \'self\' data:; frame-src https://www.google.com/recaptcha/ com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view://* nsgcepa://* application://* receiver:// https://.duosecurity.com \'self\'; child-src \'self\' com.citrix.agmacepa:// citrixng:// com.citrix.nsgclient://* vmware-view://* nsgcepa://nsgcepa application://*; form-action \'self\'; object-src \'none\'; report-uri /nscsp_violation/report_uri\""
add rewrite policy add_modified_csp_header_with_duo "HTTP.REQ.URL.CONTAINS(\"/logon/LogonPoint/tmindex.html\")" modify_csp_header_with_duo
bind authentication vserver tmvs_radius -policy add_modified_csp_header_with_duo -priority 2 -gotoPriorityExpression NEXT -type RESPONSE