Watchuseek, The Most Visited Watch Forum Site ... In The World.

vendredi 26 février 2016

Configuring the HTTPOnly attribute

If applications do not start from the user interface in IBM® WebSphere® Application Server Network Deployment 8 environments, the problem can often be attributed to a security setting within IBM WebSphere Application Server Network Deployment. In particular, if the HTTPOnly attribute is set for session cookies, the applications are not accessible.

Procedure


  1. Log on to the administrative console for IBM WebSphere Application Server Network Deployment.
  2. From the navigation pane, browse to Servers > Server Types > WebSphere spplication servers.
  3. Click the application server created for the product you want to update, for example, MXServer.
  4. From the Configuration panel, under Container Settings, click Session management.
  5. Under General properties, click Enable cookiesDo not clear this option. Click the label only.
  6. Clear the Set session cookies to HTTPOnly check box to help prevent cross-site scripting attacks.
  7. Click OK, save the changes, and then click OK.
  8. Click Save and then click OK.
  9. Navigate back to the Application servers table, and select the application server required.
  10. Click Restart to restart the application server in order to apply the changes made.


Aucun commentaire:

Enregistrer un commentaire