Forum Discussion
Robert_47833
Altostratus
Feb 04, 2013how to encrypt cookie
can I encrypt cookie in http response ,so client can't read it
4 Replies
- What_Lies_Bene1
Cirrostratus
You can. You can do so using a HTTP profile or an iRule. - Robert_47833
Altostratus
how to?
would u like to show me an example
when it arrives bigip,I hope bigip can understand this encrypted string - What_Lies_Bene1
Cirrostratus
Create a custom HTTP profile based on whatever you currently use: Local Traffic > Profiles > Services > HTTP
You'll find two fields, one to enter the name of Cookies you want to encrypt the other to enter a passphrase used for the encryption and decryption (plus a verify field I think). Fill these in as appropriate and apply the profile to your VS.
I advice you test thoroughly before doing this in a production environment. Note cookie encryption tends to break Java applications if you encrypt any SessionID cookies.
Also note that this doesn't prevent spoofing, you could copy the cookie to another machine and it would still be valid and accepted by the F5. - Robert_47833
Altostratus
the context for this profile method to encrypt/decrypt cookie can be used when cookie is added in backend server side or add via irule http::response http::cookie insert side?
everytime when bigip see this cookie in request or response .it will encrypt or decrypt?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects