Forum Discussion
KellyS_50017
Nimbostratus
Nov 11, 2009http_to_https http profile rule question
Hopefully a super-easy question about the built-in http class profile rule, http_to_https. A client of ours is saying HP's WebInspect is dinging us with a security flaw when it tries to get into areas...
hoolio
Cirrostratus
Nov 11, 2009Was the original Location header value http://something? Or was it just a path like /anon/anon.aspx? If it's the former, that might be the issue that WebInspect is reporting. If it is an http:// reference in the Location header value, you can have LTM rewrite it to HTTPS using the rewrite redirects option on a custom HTTP profile you add to the VIP.
That request is most likely to the HTTPS VIP as the response shows a persistence cookie for an HTTPS pool. Also, the redirect is coming from IIS--not LTM--as evidenced by the Server and X- headers in the response. LTM won't insert response headers like that in a response it generates itself.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects