SecurID IIS Agent cookies rsa-csrf and rsa-local are not marked as Secure
Originally Published: 2021-09-16
Article Number
Applies To
Product/Service Type: Authentication Agent for Web: IIS
Version/Condition: 8.0.x
Issue
This is seen as a security risk because this means that the cookie could potentially be stolen by an attacker who can successfully intercept and decrypt the traffic, or following a successful man-in-the-middle attack (unlikely since HSTS is enabled).
Resolution
- From the IIS Manager on the Web Agent machine, in the Connections pane, double-click server_name, and click Sites-> Default Web Site.
- In the Default Web Site Home pane, double-click RSA SecurID.
- Enable below option: Require Secure Connection to Access Protected Pages.
- Restart IIS or run an iisreset.
- Do the Authentication.
Related Articles
Enable Secure Shell on the Appliance 54Number of Views Secure Connection Between Identity Router and Identity Source (AD/LDAP) Fails When DHE Cipher Suites are Used 38Number of Views Validation URI JSP files do not work when uploaded to the secured JSP Pages section in RSA Identity Governance & Lifecycle 211Number of Views RSA SecurID Appliance 3.0 Service Pack 4 Migration Failure at Task 'Importing Certificates' 14Number of Views Absolute Secure Access - RSA Ready Implementation Guide 47Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.9 Patches and Hotfixes Readme Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?