Configuring HTTP Protocol Attributes
Determine HTTPS requirements for an Oracle APEX instance and all related applications.
Note: Require HTTPS makes APEX unreachable by the HTTP protocol. Before enabling this setting, ensure that the HTTPS protocol is enabled and configured correctly on your server.
About SSL
Learn about Secure Sockets Layer (SSL).
Secure Sockets Layer (SSL) is a protocol for managing the security of data transmitted on the Internet. For web applications, SSL is implemented by using the HTTPS protocol. Oracle recommends running APEX applications using SSL (HTTPS protocol) to prevent any sensitive data from being sent over an unencrypted (cleartext) communication channel.
Requiring HTTPS
Configure both the APEX instance and all related applications to require HTTPS by configuring the Require HTTPS and Require Outbound HTTPS attributes.
Important: If you enable Require HTTPS, it makes APEX unreachable by the HTTP protocol. Before enabling this setting, ensure that the HTTPS protocol is enabled and configured correctly on your server.
To require HTTPS in APEX:
-
Sign in to APEX Administration Services.
-
Click Manage Instance.
-
Under Instance Settings, click Security.
-
Under HTTP Protocol, configure the following:
-
Require HTTPS:
-
Always - Enforces HTTPS for all applications (including the APEX development and administration applications) to require HTTPS.
If set to Always, the Strict-Transport-Security Max Age attribute displays. Use this field to specify the time period in seconds during which the browser shall access the server with HTTPS only. To learn more, see field-level Help.
-
Development and Administration - Forces all internal applications within APEX (that is, App Builder, SQL Workshop, Administration Services and so on) to require HTTPS.
-
Application specific - Makes HTTPS dependent on application-level settings.
-
-
Require Outbound HTTPS - Select Yes to require all outbound traffic from an APEX instance to use the HTTPS protocol.
-
HTTP Response Headers - Enter additional HTTP response headers that APEX should send on each request for all applications. Developers can specify additional headers at the application-level. Each header has to start on a new line. Note that support for various headers differs between browsers. To learn more, see field-level Help.
-
-
Click Apply Changes.
Reversing Require HTTPS
If you enable Require HTTPS, an Instance administrator can disable it by running the following SQL statements.
To reverse Require HTTPS:
-
Connect in SQLcl or SQL Developer with the APEX engine schema as the current schema, for example:
-
On Windows:
SYSTEM_DRIVE:\ sql /nolog SQL> CONNECT SYS as SYSDBA Enter password: SYS_password -
On UNIX and Linux:
$ sql /nolog SQL> CONNECT SYS as SYSDBA Enter password: SYS_password
-
-
Run the following statement:
BEGIN APEX_INSTANCE_ADMIN.SET_PARAMETER('REQUIRE_HTTPS', 'N'); commit; end; /
Reversing Require Outbound HTTPS
If you enable Require Outbound HTTPS, an Instance administrator can disable it by running the following SQL statements.
To reverse Require Outbound HTTPS:
-
Connect in SQLcl or SQL Developer with the APEX engine schema as the current schema, for example:
-
On Windows:
SYSTEM_DRIVE:\ sql /nolog SQL> CONNECT SYS as SYSDBA Enter password: SYS_password -
On UNIX and Linux:
SYSTEM_DRIVE:\ sql /nolog SQL> CONNECT SYS as SYSDBA Enter password: SYS_password
-
-
Run the following statement:
BEGIN APEX_INSTANCE_ADMIN.SET_PARAMETER('REQUIRE_OUT_HTTPS', 'N'); commit; end; /
Configuring Additional Response Headers
Enter additional HTTP response headers that APEX should send on each request, for all applications.
To configure additional response headers:
-
Sign in to APEX Administration Services.
-
Click Manage Instance.
-
Under Instance Settings, click Security.
-
Locate HTTP Protocol.
-
Require HTTPS - Makes Oracle APEX unreachable by the HTTP protocol. Options include:
Note: Before enabling Require HTTPS, ensure that the HTTPS protocol is enabled and configured correctly on your server.
-
Always - Enforces HTTPS for all applications (including the Oracle APEX development and administration applications) to require HTTPS.
If set to Always, the Strict-Transport-Security Max Age attribute displays. Use this field to specify the time period in seconds during which the browser shall access the server with HTTPS only.
-
For Development and Administration - Forces all internal applications within Oracle APEX (such as App Builder, SQL Workshop, Oracle APEX Administration Services (Administration Services) and so on) to require HTTPS.
-
Application specific - Makes HTTPS dependent on the Secure session cookie attribute in the authentication schemes of your applications.
-
-
Require Outbound HTTPS - Select Yes to require all outbound traffic from an Oracle APEX instance to use the HTTPS protocol.
-
HTTP Response Headers - Enter additional HTTP response headers that APEX should send on each request for all applications. Developers can also specify additional headers at application-level. Each header has to start on a new line. Support for various headers differs between browsers. To learn more, see item Help.
-
Click Apply Changes.
Tip: APEX supports Content Security Policy (CSP) through the use of HTTP response headers. To learn more about cofigurng CSP, see Configuring Content Security Policy (CSP) in Oracle APEX App Builder User’s Guide.