Forum Discussion
Robert_47833
Altostratus
Feb 04, 2013how to encrypt cookie
can I encrypt cookie in http response ,so client can't read it
What_Lies_Bene1
Cirrostratus
Feb 04, 2013Create a custom HTTP profile based on whatever you currently use: Local Traffic > Profiles > Services > HTTP
You'll find two fields, one to enter the name of Cookies you want to encrypt the other to enter a passphrase used for the encryption and decryption (plus a verify field I think). Fill these in as appropriate and apply the profile to your VS.
I advice you test thoroughly before doing this in a production environment. Note cookie encryption tends to break Java applications if you encrypt any SessionID cookies.
Also note that this doesn't prevent spoofing, you could copy the cookie to another machine and it would still be valid and accepted by the F5.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects