# # This configuration file allows a diskfull install to access the install images # via http. It also allows the xCAT documentation to be accessed via # http://localhost/xcat-doc/ # Updates to xCAT/xcat.conf should also be made to xCATsn/xcat.conf # AliasMatch ^/install/(.*)$ "/install/$1" AliasMatch ^/tftpboot/(.*)$ "/tftpboot/$1" AllowOverride None Order allow,deny Allow from all Options +Indexes +FollowSymLinks Header always append X-Frame-Options SAMEORIGIN Header always append X-XSS-Protection "1; mode=block" Header always append X-Content-Type-Options nosniff Header always append Content-Security-Policy "script-src 'self' 'unsafe-eval'" Header always append X-Permitted-Cross-Domain-Policies none AllowOverride None Order allow,deny Allow from all Options +Indexes +FollowSymLinks Header always append X-Frame-Options SAMEORIGIN Header always append X-XSS-Protection "1; mode=block" Header always append X-Content-Type-Options nosniff Header always append Content-Security-Policy "script-src 'self' 'unsafe-eval'" Header always append X-Permitted-Cross-Domain-Policies none Alias /xcat-doc "/opt/xcat/share/doc" AllowOverride None Order allow,deny Allow from all Options +Indexes +FollowSymLinks Header always append X-Frame-Options SAMEORIGIN Header always append X-XSS-Protection "1; mode=block" Header always append X-Content-Type-Options nosniff Header always append Content-Security-Policy "script-src 'self' 'unsafe-eval'" Header always append X-Permitted-Cross-Domain-Policies none ServerTokens Prod