Hi, security staff requires the Domino server to set the ‘secure’ flag of the DomAuthSessId cookie, so it is used only in https.
This is the cookie that our Domino is sending to the browser:
Name:DomAuthSessId
Domain/Host:www.mydomain.com
Path:/
Expires:End of session
Secure/Server Secure:No
Data/Content:1856F4B1F8E161907EBA7687950F2103
Does anybody know how to make Domino send the cookie with the ‘secure’ flag activated?
Thanks a lot,
J R