Forum Discussion
KellyS_50017
Nimbostratus
Nov 11, 2009http_to_https http profile rule question
Hopefully a super-easy question about the built-in http class profile rule, http_to_https. A client of ours is saying HP's WebInspect is dinging us with a security flaw when it tries to get into areas...
KellyS_50017
Nimbostratus
Nov 11, 2009Sure. You've seen the request and response block from WebInspect, here's the text accompanying it, with the url anon'd.
SSL Cookie Not Used
Summary: This policy states that any area of the website or web application that contains sensitive information or access to privileged
functionality such as remote site administration requires that all cookies are sent via SSL during an SSL session. The URL:
https://anon.com:443/Anon01/Anon01.aspx has failed this
policy. If a cookie is marked with the "secure" attribute, it will only be transmitted if the communications channel with the host
is a secure one. Currently this means that secure cookies will only be sent to HTTPS (HTTP over SSL) servers. If secure is not
specified, a cookie is considered safe to be sent in the clear over unsecured channels.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects