Re: Secure Cookies in Asp.net web application.

From: Shel Blauman [MSFT] (sheldonb_at_online.microsoft.com)
Date: 06/26/03


Date: Thu, 26 Jun 2003 08:00:58 -0700


Forwarding to Aspnet.Security.

Shel

-- 
This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm
"Raja Narayanan" <rajanarayanantvl@hotmail.com> wrote in message
news:0b3e01c33bd5$f7ad7a00$a301280a@phx.gbl...
> Hi to all,
> How to set 'secure cookie' for a ASP.NEW web application,
> the web application uses (SSL) https:// and the IE browser
> 6.0 'Internet options' are set to 'override automatic
> cookie handling' to prompt the cookie. So while browsing
> the web application on internet, the browser shows
> a 'Privacy Alert' to Allow or Block the cookie on the
> first Login.aspx page.
> So i can view the 'ASP.NET_SessionId' in non secure
> manner. It shows on the dialog box Secure No. So to change
> it to Secure Yes, what i have to do for my entire web
> application.
> By default 'ASP.NET_SessionId' is generated by the web
> application.
> My .Net FrameWork 1.1.4322 version. And IIS 5.0 Version.
>
> My Question is,
> 1) Isn't it any possbilities in web.config file? or others?
> Explain pls..?
>
> With Advance Thankx
> Raja.N
>


Relevant Pages

  • Reg: Secure Cookies in Asp.net web application.
    ... How to set 'secure cookie' for a ASP.NEW web application, ... the web application uses https:// and the IE browser ... 'Internet options' are set to 'override automatic ...
    (microsoft.public.dotnet.security)
  • Re: How to use SSL for login page only
    ... when a cookie itself has ... Joe Kaplan-MS MVP Directory Services Programming ... section will take care of the Secure flag. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • OT: Re: Are cookies so important that a dealer would sacrifice a sale over one?
    ... cookie. ... The most secure and relaible involves server ... > I've lost shopping cart items many times because I wanted to use ... >> of cookies is fraught with security issues. ...
    (rec.collecting.coins)
  • Re: Secure Cookies in Asp.net web application.
    ... Use of included script samples are subject to the terms specified at ... > How to set 'secure cookie' for a ASP.NEW web application, ... > the web application uses https:// and the IE browser ... > cookie handling' to prompt the cookie. ...
    (microsoft.public.dotnet.security)
  • Re: Security of Password-Managers
    ... > When I lose the piece of paper, I've got the disk. ... with a verbal secret called "the cookie". ... The method is far from completely secure. ... not a gasthaus in the area that didn't have the Bitburger logo and Simon ...
    (Security-Basics)