---
title: Add Security Headers
slug: edgemanager/quickstart-guide/add-security-headers
description: Learn how to add security headers to Litmus Edge Manager. 
docTags: 
createdAt: 2024-02-12T20:38:26.216Z
---

Complete the following steps to add new security headers to Litmus Edge Manager.&#x20;

# Security Header Directives

Refer to the following directives when completing the steps below.&#x20;

```shell
add_header Content-Security-Policy "default-src 'self' https://static.zdassets.com https://ekr.zdassets.com https://ekr.zendesk.com https://litmus.zendesk.com https://*.zopim.com https://zendesk-eu.my.sentry.io wss://litmus.zendesk.com wss://*.zopim.com; img-src 'self' https://litmus.zendesk.com https://media.smooch.io https://v2assets.zopim.io https://static.zdassets.com data:; font-src 'self' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://api.smooch.io https://cdn.segment.com/ https://www.googletagmanager.com https://static.zdassets.com; style-src * blob: 'unsafe-inline'; connect-src 'self' https://api.segment.io/ https://ekr.zdassets.com https://litmus.zendesk.com wss://widget-mediator.zopim.com https://api.smooch.io https://*.config.smooch.io wss://api.smooch.io;";
add_header X-Frame-Options SAMEORIGIN;
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options nosniff;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload; always;";
add_header Referrer-Policy "strict-origin-when-cross-origin";
```

# Add New Security Headers

1. Connect to Litmus Edge Manager through SSH. Refer to [Access Litmus Edge Manager](docId\:w3uHZQ4tSrH7OLjhuLt0A) for default login credentials.&#x20;
2. Open or create the following file: `/etc/nginx/snippets/sec-hdrs.conf`.&#x20;
3. If the file exists, run the following command to create a backup by running the copy command.&#x20;
   `cp /etc/nginx/snippets/sec-hdrs.conf /etc/nginx/snippets/sec-hdrs.conf.bak`
4. Add or modify the file by using the directives above in *Security Header Directives*.
   - Use the `add_header` directive to add your header. Ensure that each `add_header` statement ends with a semicolon (;).
   - If a header has components separated by semicolons, use double quotation marks ("") to enclose the text.&#x20;
5. After editing the file, validate the Nginx configuration with the following command.&#x20;
   `sudo nginx -t`
6. If the validation passes without errors, reload Nginx to apply the changes with the following command.&#x20;
   `sudo systemctl reload nginx`

