JR44260 Cookies in Information Server are not secure This change provides a means to secure the cookies used in Information Server by - setting the Secure attribute so that the cookies are only transferred over secure https communication channels using SSL encryption - setting the HTTPOnly attribute so that cookies are not passed to JavaScript running in the browser Setting the HTTPOnly attribute requires a manual configuration change in WebSphere as described in the "Securing Cookies In Information Server" technote (http://www.ibm.com/support/docview.wss?uid=swg21622209). Setting the Secure attribute requires a manual configuration change in WebSphere as well as a manual change in ISF. In addition, all tiers must be configured for HTTPS as described in the Information Server Administration Guide. Once the Secure attribute is configured, client login will only work over https connections using a secure port. Detailed instructions for configuring HTTPS and the Secure attribute for cookies, is described in the "Securing Cookies In Information Server" technote (http://www.ibm.com/support/docview.wss?uid=swg21622209).