Hiding Server Identity

By default, Web Transaction Server (WebTS) sends all responses with the HTTP Server header as:

Server: Web Transaction Server For ClearPath MCP 18.0

By identifying to users the name of the server, there is a small risk that someone could use the knowledge of the particular server type and level to formulate an attack against any known weaknesses in that server.

To avert this risk, you can customize the Server header using the Web Transaction Server custom headers feature. As a result, you can send customer-defined text in place of the Web Transaction Server default.

For example, the server could be defined (most likely at the Web site level) as:

Server: An HTTP/1.1 server