IBM Support

PM94195: When you set "Restrict cookies to HTTPS session cookies" on the application server, the cookie is not secure.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • The JSESSIONID cookie is set as an unsecured cookie when you
    set the option, "Restrict cookies to HTTPS sessions" on the
    application server.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Customers who use the setting,              *
    *                  listenerMode=false, in the                  *
    *                  splicer.properties file for eXtreme Scale   *
    *                  HTTP session management and enable the      *
    *                  "Restrict cookies to HTTPS sessions" option *
    *                  on the application server                   *
    ****************************************************************
    * PROBLEM DESCRIPTION: The JSESSIONID cookie is set as a       *
    *                      non-secure cookie.                      *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When the "Restrict cookies to HTTPS sessions" option is set on
    the application server, the JSESSIONID cookie needs to be set
    as a secure cookie.
    

Problem conclusion

  • WebSphere eXtreme Scale now correctly sets the cookie as secure
    when the "Restrict cookies to HTTPS sessions" option is set on
    the application server.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM94195

  • Reported component name

    WS EXTREME SCAL

  • Reported component ID

    5724X6702

  • Reported release

    860

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-07-31

  • Closed date

    2013-08-06

  • Last modified date

    2013-08-06

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WS EXTREME SCAL

  • Fixed component ID

    5724X6702

Applicable component levels

  • R860 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSTVLU","label":"WebSphere eXtreme Scale"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"860","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
06 August 2013