SecurID IIS Agent cookies rsa-csrf and rsa-local are not marked as Secure
Originally Published: 2021-09-16
Article Number
Applies To
Product/Service Type: Authentication Agent for Web: IIS
Version/Condition: 8.0.x
Issue
This is seen as a security risk because this means that the cookie could potentially be stolen by an attacker who can successfully intercept and decrypt the traffic, or following a successful man-in-the-middle attack (unlikely since HSTS is enabled).
Resolution
- From the IIS Manager on the Web Agent machine, in the Connections pane, double-click server_name, and click Sites-> Default Web Site.
- In the Default Web Site Home pane, double-click RSA SecurID.
- Enable below option: Require Secure Connection to Access Protected Pages.
- Restart IIS or run an iisreset.
- Do the Authentication.
Related Articles
How to update Card Manager to conform to the subject DN configuration 7Number of Views Secure Connection Between Identity Router and Identity Source (AD/LDAP) Fails When DHE Cipher Suites are Used 31Number of Views Validation URI JSP files do not work when uploaded to the secured JSP Pages section in RSA Identity Governance & Lifecycle 200Number of Views Enable Secure Shell on the Appliance 53Number of Views SecurID: RSA ACE/Server (Authentication Manager) is not running 80Number of Views
Trending Articles
Don't see what you're looking for?