Forum Discussion
KellyS_50017
Nimbostratus
Nov 11, 2009http_to_https http profile rule question
Hopefully a super-easy question about the built-in http class profile rule, http_to_https. A client of ours is saying HP's WebInspect is dinging us with a security flaw when it tries to get into areas...
KellyS_50017
Nimbostratus
Nov 11, 2009I'm understanding more, I think. Setting cookies to Secure in our asp.net code wouldn't help, because that only says "only transmit cookies over ssl", right? It doesn't actually help because between the F5 and our web servers, you can only do SSL.
So what are my options? How can I tell the F5 not to return cookie data over non-ssl? Or can I turn on cookie encryption on the F5?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects