HTTP/1.1 301 Moved Permanently
Content-Length: 0
Connection: keep-alive
Server: CloudFront
Date: Wed, 06 May 2020 15:49:05 GMT
Location: https://www.openbank.de/
Access-Control-Max-Age: 3600
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Encoding: UTF-8
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Content-Security-Policy: upgrade-insecure-requests
X-Cache: Miss from cloudfront
Via: 1.1 833189e24f3e31812a47b595ff310a14.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: EWR52-C2
X-Amz-Cf-Id: OL-Qb5AXiqiXt7lNrRVCqx2hyygQnbCSZBPUv9rx_8e690rqp122bQ==
HTTP/2 200
content-type: text/html; charset=UTF-8
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains; preload
link: <https://www.openbank.de/>; rel="canonical", <https://www.openbank.de/>; rel="shortlink"
link: <https://www.openbank.es/>; rel="alternate"; hreflang="es-ES"
link: <https://www.openbank.de/>; rel="alternate"; hreflang="de-DE"
link: <https://www.openbank.pt/>; rel="alternate"; hreflang="pt-PT"
link: <https://www.openbank.nl/>; rel="alternate"; hreflang="nl-NL"
link: <https://www.openbank.es/en/>; rel="alternate"; hreflang="en-ES"
x-ua-compatible: IE=edge
content-language: de
x-content-type-options: nosniff
x-frame-options: sameorigin
last-modified: Wed, 06 May 2020 15:49:06 GMT
etag: "1588780146-gzip"
x-xss-protection: 1; mode=block
content-security-policy: upgrade-insecure-requests; default-src 'self' api.openbank.es api.stg.openbank.es api.qa.openbank.es; script-src 'self' 'unsafe-inline' 'unsafe-eval' snap.licdn.com track.adform.net *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt https://maps.googleapis.com simuladores-pre.afi.es simuladores.afi.es *.nr-data.net https://browseranalytic.com https://www.google.com *.gstatic.com https://tags.tiqcdn.com *.google-analytics.com *.tealiumiq.com https://tealium.hs.llnwd.net https://*.g.doubleclick.net *.amazonaws.com *.youtube.com *.googleadservices.com *.ads-twitter.com *.facebook.net *.ytimg.com api-ob.nd.nudatasecurity.com *.googletagmanager.com *.we-stats.com static.browseranalytic.com optimize.google.com bat.bing.com blob:; style-src 'self' 'unsafe-inline' optimize.google.com https://fonts.googleapis.com *.amazonaws.com *.openbankwealth.com *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt api-ob.nd.nudatasecurity.com https://maxcdn.bootstrapcdn.com; img-src 'self' px.ads.linkedin.com *.idealista.com track.adform.net www.financeads.net t.teads.tv data: 'unsafe-inline' *.amazonaws.com *.googletagmanager.com https://maps.googleapis.com *.gstatic.com *.google-analytics.com *.doubleclick.net *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt *.google.com *.google.es *.google.ie *.facebook.com api-ob.nd.nudatasecurity.com https://aax-eu.amazon-adsystem.com bat.bing.com tr.outbrain.com www.linkedin.com s-central1-madrid-investing.cloudfunctions.net tbl.tradedoubler.com dmpue.el-mundo.net ; media-src 'self' 'unsafe-inline' *.amazonaws.com *.openbank.es *.youtube.com; frame-src 'self' optimize.google.com https://www.google.com *.gstatic.com *.youtube.com simuladores-pre.afi.es simuladores.afi.es *.doubleclick.net api-ob.nd.nudatasecurity.com https://openjobs.openbank.es *.clientes.openbank.es blob: api.openbank.es api.stg.openbank.es api.qa.openbank.es; child-src https://www.google.com *.gstatic.com *.youtube.com simuladores-pre.afi.es simuladores.afi.es *.doubleclick.net api-ob.nd.nudatasecurity.com https://openjobs.openbank.es *.clientes.openbank.es blob: api.openbank.es api.stg.openbank.es api.qa.openbank.es; font-src 'self' *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt maxcdn.bootstrapcdn.com data: https://fonts.gstatic.com *.openbankwealth.com api-ob.nd.nudatasecurity.com maxcdn.bootstrapcdn.com; connect-src 'self' www.google-analytics.com *.openbank.pt *.openbank.nl *.openbank.de *.openbank.es *.nr-data.net *.we-stats.com *.tealiumiq.com api-ob.nd.nudatasecurity.com decollector.tealeaf.ibmcloud.com op.browseranalytic.com api.openbank.es api.stg.openbank.es api.qa.openbank.es; frame-ancestors 'self' *.openbank.de *.openbank.nl *.openbank.pt *.openbank.es api.paycomet.com https://www.paytpv.com; object-src 'self' api.openbank.es api.stg.openbank.es api.qa.openbank.es
x-content-security-policy: default-src 'self' api.openbank.es api.stg.openbank.es api.qa.openbank.es; script-src 'self' 'unsafe-inline' 'unsafe-eval' snap.licdn.com track.adform.net *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt https://maps.googleapis.com simuladores-pre.afi.es simuladores.afi.es *.nr-data.net https://browseranalytic.com https://www.google.com *.gstatic.com https://tags.tiqcdn.com *.google-analytics.com *.tealiumiq.com https://tealium.hs.llnwd.net https://*.g.doubleclick.net *.amazonaws.com *.youtube.com *.googleadservices.com *.ads-twitter.com *.facebook.net *.ytimg.com api-ob.nd.nudatasecurity.com *.googletagmanager.com *.we-stats.com static.browseranalytic.com optimize.google.com bat.bing.com blob:; style-src 'self' 'unsafe-inline' optimize.google.com https://fonts.googleapis.com *.amazonaws.com *.openbankwealth.com *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt api-ob.nd.nudatasecurity.com https://maxcdn.bootstrapcdn.com; img-src 'self' *.idealista.com px.ads.linkedin.com track.adform.net www.financeads.net t.teads.tv data: 'unsafe-inline' *.amazonaws.com *.googletagmanager.com https://maps.googleapis.com *.gstatic.com data: *.google-analytics.com *.doubleclick.net *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt *.google.com *.google.es *.google.ie *.facebook.com api-ob.nd.nudatasecurity.com https://aax-eu.amazon-adsystem.com bat.bing.com tr.outbrain.com www.linkedin.com s-central1-madrid-investing.cloudfunctions.net tbl.tradedoubler.com dmpue.el-mundo.net ; media-src 'self' 'unsafe-inline' *.amazonaws.com *.openbank.es *.youtube.com; frame-src 'self' optimize.google.com https://www.google.com *.gstatic.com *.youtube.com simuladores-pre.afi.es simuladores.afi.es *.doubleclick.net api-ob.nd.nudatasecurity.com https://openjobs.openbank.es *.clientes.openbank.es blob: api.openbank.es api.stg.openbank.es api.qa.openbank.es; child-src https://www.google.com *.gstatic.com *.youtube.com simuladores-pre.afi.es simuladores.afi.es *.doubleclick.net api-ob.nd.nudatasecurity.com https://openjobs.openbank.es *.clientes.openbank.es blob: api.openbank.es api.stg.openbank.es api.qa.openbank.es; font-src 'self' *.openbank.es *.openbank.de *.openbank.nl *.openbank.pt maxcdn.bootstrapcdn.com data: https://fonts.gstatic.com *.openbankwealth.com api-ob.nd.nudatasecurity.com maxcdn.bootstrapcdn.com; connect-src 'self' www.google-analytics.com *.openbank.es *.nr-data.net *.we-stats.com *.tealiumiq.com api-ob.nd.nudatasecurity.com decollector.tealeaf.ibmcloud.com op.browseranalytic.com api.openbank.es api.stg.openbank.es api.qa.openbank.es; frame-ancestors 'self' *.openbank.de *.openbank.nl *.openbank.pt *.openbank.es api.paycomet.com https://www.paytpv.com; object-src 'self' api.openbank.es api.stg.openbank.es api.qa.openbank.es
pragma: no-cache
cache-control: no-cache, no-store, must-revalidate
expires: Wed, 06 May 2020 15:49:06 GMT
date: Wed, 06 May 2020 15:49:06 GMT
access-control-allow-credentials: false
access-control-max-age: 86400
access-control-allow-methods: GET,POST,HEAD
|