Forum Discussion
Steve_Brown_882
Nov 06, 2008Historic F5 Account
Masking jsessionid with ASM
I am looking for some input on how we can resolve an issue we have with a weblogic based application which is behind an F5 with ASM. The problem is that we would like to mask the jsesionid from the ur...
hoolio
Cirrostratus
Nov 11, 2008If you (or your dev team) is willing to block clients who don't support cookies, couldn't you avoid the possible session ID leakage issue by not using the jsessionid in the URI?
I'd still suggest that using SSL for all but the initial request would provide better security and definitely better functionality for all clients--including those that don't support cookies.
That doesn't answer your question about enforcing the dynamic session ID in the URI. Does anyone know if you need to configure the dynamic session ID in URI regex as well as the extraction in order to validate the session ID?
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
