SecurID IIS Agent cookies rsa-csrf and rsa-local are not marked as Secure
Originally Published: 2021-09-16
Article Number
Applies To
Product/Service Type: Authentication Agent for Web: IIS
Version/Condition: 8.0.x
Issue
This is seen as a security risk because this means that the cookie could potentially be stolen by an attacker who can successfully intercept and decrypt the traffic, or following a successful man-in-the-middle attack (unlikely since HSTS is enabled).
Resolution
- From the IIS Manager on the Web Agent machine, in the Connections pane, double-click server_name, and click Sites-> Default Web Site.
- In the Default Web Site Home pane, double-click RSA SecurID.
- Enable below option: Require Secure Connection to Access Protected Pages.
- Restart IIS or run an iisreset.
- Do the Authentication.
Related Articles
Error "Key negotiation exchange failed. Server response was CANCELLED" with RSA Authentication Agent API 8.5 and later 83Number of Views Change Items depends on Account Creation marked as 'Rejected' If the Create Account Request 'Cancelled' without showing th… 1Number of Views IIS Hangs on Restart with Many Application Pools 38Number of Views Exclusion in workflow approval node not working if Out Of Office is set for an approver in RSA Identity Governance & Lifec… 52Number of Views DLP - Issue with Scanning Exchange Mailboxes 34Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes: Cloud Access Service and RSA Authenticators RSA Release Notes for RSA Authentication Manager 8.8 RSA-2026-04: RSA Governance and Lifecycle Security Update for SUSE Linux Enterprise Server Vulnerabilities
Don't see what you're looking for?