Forum Discussion
Torti
Cirrus
Nov 13, 2014ASM cookie without value not RFC-compliant
Hi,
we are running 11.5.1
...
Vesna_King_1375
Nimbostratus
Sep 28, 2015We have upgraded from 11.2 to 11.6 and now instead of "ASM modified" we are seeing "Cookie not RFC-Compliant". The problem is that the client's browser sends empty cookies which are RFC compliant. This seems to be happening only for Chrome users (mostly on Mac OS X10 and Windows 7).
ASM detects issue only for its own cookies (TSxxxxxx=;) and this behaviour does not seem to be in line with article 7776.
The impact to the user is that he will not be able to connect to the website until the cookies are completely cleared. The possible workaround is to downgrade "Cookie not RFC-compliant" violation, but this would allow various genuine attacks against cookies to get passed the firewall.
Does anyone know why was there a change in the ASM behaviour?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects