Forum Discussion
how to setup persistence to concatenate jvmRoute with JSESSIONID to generate final SESSIONID
This is for encrypting Cookie content to improve security. It is a PCI requirement.
- sirwinstonMar 14, 2017
Nimbostratus
But I don't think encrypting the JSESSIONID cookie improves security at all. It is just a random value that is a pointer to a session object in an application server (e.g. Tomcat). Encrypting it doesn't do anything but turning it into another random value. If a hacker gets hold of the encrypted JSESSIONID (s)he can still just pass it along with a request and it will get descrypted on the fly by LTM.
You could even argue that encryption even weakens your security as your are (arguably low) using CPU power for unnecessary stuff.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
