Forum Discussion
Cookie encryption and RAW data required
Dear all,
Have a query on cookie
What is the Recommended Industrial best practise for cookie encryption
One of our customer needs cookie encryption enabled.. at the same time... Part of of cookies should be available RAW for his application to work..
Need your suggestions/ideas to take this forward
- Sonne_133164
Nimbostratus
question is whether there is anything sensitive within the cookie, why you need to encrypt cookie? using https against mitm isn't enough? is client storing this cookie for a longer period and you expect someone will access it, tamper it, etc...?
for the best practices:
- limit the amount of sensitive information stored in the cookie.
- limit the subdomains and paths to prevent interception by another application.
- enforce SSL so the cookie isn’t sent in cleartext.
- make the cookie HttpOnly
perhaps you can read more at https://www.owasp.org/index.php/Session_Management_Cheat_SheetCookies
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com