0 Replies Latest reply: Apr 7, 2011 6:35 AM by 853586 RSS

    How To Disable http methods

    853586
      I'm using Oracle Iplanet Proxy Server Version: 4.0.15

      I want to disable some of the http methods supported by default. When I telnet to the port and send "OPTIONS * HTTP/1.0" , I can see the methods allowed.
      -----
      Trying 127.0.0.1...
      Connected to localhost.
      Escape character is '^]'.
      OPTIONS * HTTP/1.0

      HTTP/1.1 200 OK
      Server: Oracle-iPlanet-Proxy-Server/4.0
      Date: Thu, 07 Apr 2011 11:11:28 GMT
      Content-length: 0
      Allow: HEAD, GET, PUT, POST, DELETE, TRACE, OPTIONS, MOVE, INDEX, MKDIR, RMDIR, CONNECT, PROPFIND, PROPPATCH, MKCOL, COPY, LOCK, UNLOCK, PURGE
      Connection: close
      -----

      How can I disable the methods other than HEAD, GET, PUT, POST ? I tried the solution suggested for Web Server but it did not work. Which is,

      <Client method="TRACE">
      AuthTrans fn="set-variable"
      remove-headers="transfer-encoding"
      set-headers="content-length: -1"
      error="501"
      </Client>

      -tarkan