Access Management 7.3.2

Secure cookies by default

When using HTTPS, mark all your cookies as secure, which means they are only transmitted over HTTPS protocols.

This flag is useful for sites that allow both HTTPS and HTTP traffic, since it protects from HTTP redirection carrying session cookies across unencrypted connections.

  1. In the AM admin UI, go to Configure > Server Defaults > Security > Cookie.

  2. Enable the Secure Cookie option.

  3. Click Save Changes.

  4. Restart AM or the container where it runs.