Link to home
Start Free TrialLog in
Avatar of emtechadmin
emtechadminFlag for United Arab Emirates

asked on

Exchange 2010 cookie

Dear Experts,

we have Exchange 2010 SP2 running on server 2008R2,

How can you ensure that all cookies  are sent only on SSL-secured connection, if not how to force ssl on it.

Thanks
Avatar of Member_2_6515809
Member_2_6515809

Are you referring to the cookies for Outlook Web Access? If so, by default Outlook Web Access is SSL-only anyway so this will already be happening unless you've specifically enabled OWA on standard HTTP.
Avatar of emtechadmin

ASKER

HI BlueCompute,

Thanks for your response.

our customer received below advise form it audit, can you please explain what it means,

Missing Secure Attribute in Encrypted Session (SSL) Cookie:
it is best business practice that any cookies that sent over (Set-cookie) an ssl connection to explicitly state secure on them

Thanks
SOLUTION
Avatar of Member_2_6515809
Member_2_6515809

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Avatar of Simon Butler (Sembee)
Simon Butler (Sembee)
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial