Jump to content
Welcome to our new Citrix community!

How to remove 'X-Frame-Options" out from StoreFront?


poomz

Recommended Posts

Hi. 

 

I cannot open StoreFront web and found error at below

 

Config Error:   Cannot add duplicate collection entry of type 'add' with unique key attribute 'name' set to 'X-Frame-Options'

Config File \\?\D:\inetpub\wwwroot\Citrix\storeWeb\web.config

 

Config Source:

399:   <add name="X-Frame-Options" value="deny" />

 

This Storefront 's Security hardening about IIS and ignore to use this.  Customer informed us to ignore this from Citrix StoreFront.    

 

I can remove this X-Frame-Options from Web.config or not?  How can I configure to ignore this.  

 

Regards,

 

Poomz

 

Link to comment
Share on other sites

13 hours ago, Sam Jacobs said:

The error message seems to be saying that you have the key X-Frame-Options twice in the web.config file.

Did you try removing the duplicate?

Due to Hardening for Server as used IIS that's blocked about X-Frame-Options.   I have removed X-Frame-Options, already.  After remove it out from Web.config 

Besides deleting this file I have to delete Content-Security-Policy  ,  X-XSS-Protection  and X-Content-type-Options.

After then I can open StoreFront Web.  I don't sure that it's effected with other problem in future or not.   

 

Regards,

 

 

1.jpg

Link to comment
Share on other sites

1 minute ago, Sam Jacobs said:

I'm a bit confused. You said that you removed the X-Frame-Options, but you're showing an image with the option still in web.config.

 

For our attached file's picture that I have showed you from other lab.

I have displayed you contents in red box as deleted on some site.

Link to comment
Share on other sites

  • 3 weeks later...

Follow the attached file for HTTP Response Headers to add X-XSS-Protection, X-Frame-Options and Content-Security-Policy. that's hardening to use.  If I deleted these. Citrix Storefront can be opened normally as that's meaning that no need to delete contents at web.config (citrix/storeweb)

 

So I need to configure to follow attached file.  How can I fix the problem so I can open Citrix Storefront normally?

 

Regards,

1.jpg

1.jpg

Link to comment
Share on other sites

  • 1 year later...

Hi,

 

I am too facing the same issue , after I added the above settings under HTTP response Header , the citrix webpage show same error as mention above and not opening, But when I delete those setting the citrix page started working. Please can anyone help here how we can fix this issue as we need to do hardening of the storefront server

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...