Allow arbitrary HTTP/S headers to be configured in responses.
Ref: RT#24049 A customer's security scanner has detected the lack of an HSTS header sent by the control agent. While it's unlikely for this header to actually be used, it would be a good idea to allow any sort of header to be configurable.
Edited by Tomek Mrugalski