Forum Discussion
Steve_Brown_882
Nov 06, 2008Historic F5 Account
Masking jsessionid with ASM
I am looking for some input on how we can resolve an issue we have with a weblogic based application which is behind an F5 with ASM. The problem is that we would like to mask the jsesionid from the ur...
hoolio
Cirrostratus
Nov 06, 2008Doh... actually if the client is being sent the jsessionid in links because it doesn't support cookies, then you won't be able to use the ASM cookie to track whether the server set the jsessionid in a response. Any request from the client with a jsessionid in the URI would be blocked if they didn't have an ASM cookie with the correct hash. Likewise, if someone was able to get the jsessionid from the client and steal the ASM cookie within the timeout period, they'd still be able to steal the session.
I guess this goes back to the question of what are you security concerns with the jsessionid?
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
