IBM Support

PM95595: Secure IBMID and IBMSessionHandle cookies when you use HTTP session replication.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Secure IBMID and IBMSessionHandle cookies when you use
    HTTP session replication on web applications.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of WebSphere eXtreme Scale for HTTP   *
    *                  session replication for web applications    *
    *                  who use secure cookies that are             *
    *                  restricted to HTTPS communication.          *
    ****************************************************************
    * PROBLEM DESCRIPTION: The eXtreme Scale cookies set on the    *
    *                      client browser are not secure.          *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    If secure cookies are configured, only the JSESSIONID cookie
    is secure.  ‚  The IBMID and IBMSessionHandle cookies are still
    marked as not secure.
    

Problem conclusion

  • The HTTP session client component has been updated to secure
    the IBMID and IBMSessionHandle cookies when the JSESSIONID
    cookie is already secure.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM95595

  • Reported component name

    WS EXTREME SCAL

  • Reported component ID

    5724X6702

  • Reported release

    860

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-08-21

  • Closed date

    2013-08-23

  • Last modified date

    2013-08-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WS EXTREME SCAL

  • Fixed component ID

    5724X6702

Applicable component levels

  • R860 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSTVLU","label":"WebSphere eXtreme Scale"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"860","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
23 August 2013