Andy
I have exactly the same errors in my new installation. Never played with Grommuinio Files before so having to find help via internet reading or trawling the Grommunio server, as the Grommunio Files documentation doesn't appear to have been published yet (just placeholders are present). I have found the first 2 and last errors can be modified in the following file:-
/usr/share/grommunio-common/nginx/security.conf
However, first time I tried this I broke my test server to the point that nginx would not start, so had to remove my edits to get it running again. Have subsequently rebuilt my test server as wanted to get the Files Data directory onto a NFS share as it will only be used as a 'cloud store' for my iPhone photos to avoid using iCloud.
EDIT: I have also found a second file with these settings in:-
/usr/share/grommunio-admin-common/nginx.d/security.conf
but making changes to either of these files makes no change to the errors reported (first 2 and last one):-
The "X-Robots-Tag" HTTP header is not set to "noindex, nofollow". This is a potential security or privacy risk, as it is recommended to adjust this setting accordingly.
The "X-XSS-Protection" HTTP header does not contain "1; mode=block". This is a potential security or privacy risk, as it is recommended to adjust this setting accordingly.
Your web server is not properly set up to resolve "/.well-known/webfinger". Further information can be found in the documentation ↗.
Your web server is not properly set up to resolve "/.well-known/nodeinfo". Further information can be found in the documentation ↗.
Your web server is not properly set up to resolve "/.well-known/caldav". Further information can be found in the documentation ↗.
Your web server is not properly set up to resolve "/.well-known/carddav". Further information can be found in the documentation ↗.
You have not set or verified your email server configuration, yet. Please head over to the Basic settings in order to set them. Afterwards, use the "Send email" button below the form to verify your settings.
The PHP OPcache module is not properly configured. See the documentation ↗ for more information.
The PHP OPcache module is not loaded. For better performance it is recommended to load it into your PHP installation.
The "Referrer-Policy" HTTP header is not set to "no-referrer", "no-referrer-when-downgrade", "strict-origin", "strict-origin-when-cross-origin" or "same-origin". This can leak referer information. See the W3C Recommendation ↗.
The reported links take you to articles for NextCloud but the paths, and filenames are very different making sorting out the errors a bit like 'finding needles in haystacks' . Would be very helpful if anyone who has managed to sort these errors could give us (the less enlightened) some clues as to how to fix these errors. The errors report security ricks so would be nice to fix the error before using Grommunio Files in anger!!
For those also dangling their feet into Files for the first time, the php config file is here:-
/var/lib/grommunio-files/config/config.php
For files in this directory 'access writes' must be maintained as grofiles:grofiles or Grommunio Files will not start (possible 500 error from Nginx. Quickly learnt `I need to install 'sudo'
zypper ref
zypper install sudo
Then edit config.php with:-
sudo -u grofiles nano /var/lib/grommunio-files/config/config.php
but make a copy of your config.php in case it dislikes your edits.
Best Regards
Mark