Configuring the HTTPOnly attribute
If applications do not start from the user interface in IBM® WebSphere® Application Server Network Deployment 8 environments, the problem can often be attributed to a security setting within IBM WebSphere Application Server Network Deployment. In particular, if the HTTPOnly attribute is set for session cookies, the applications are not accessible.
Procedure
- Log on to the administrative console for IBM WebSphere Application Server Network Deployment.
- From the navigation pane, browse to .
- Click the application server created for the product you want to update, for example, MXServer.
- From the Configuration panel, under Container Settings, click Session management.
- Under General properties, click Enable cookies. Do not clear this option. Click the label only.
- Clear the Set session cookies to HTTPOnly check box to help prevent cross-site scripting attacks.
- Click OK, save the changes, and then click OK.
- Click Save and then click OK.
- Navigate back to the Application servers table, and select the application server required.
- Click Restart to restart the application server in order to apply the changes made.

Aucun commentaire:
Enregistrer un commentaire