SecurID IIS Agent cookies rsa-csrf and rsa-local are not marked as Secure
Originally Published: 2021-09-16
Article Number
Applies To
Product/Service Type: Authentication Agent for Web: IIS
Version/Condition: 8.0.x
Issue
This is seen as a security risk because this means that the cookie could potentially be stolen by an attacker who can successfully intercept and decrypt the traffic, or following a successful man-in-the-middle attack (unlikely since HSTS is enabled).
Resolution
- From the IIS Manager on the Web Agent machine, in the Connections pane, double-click server_name, and click Sites-> Default Web Site.
- In the Default Web Site Home pane, double-click RSA SecurID.
- Enable below option: Require Secure Connection to Access Protected Pages.
- Restart IIS or run an iisreset.
- Do the Authentication.
Related Articles
Keys stored in nCipher HSM are marked as nonrecoverable even if 'enable key recovery' is set 5Number of Views RSA Authentication Manager 8.1 SP 1 patch 1 backups to a Windows Shared Folder are failing after software upgrade 243Number of Views How to secure access to the Authentication Web Service 2Number of Views Events and incidents mark as deleted automatically 17Number of Views How to Restrict users from using certain PIN's that are less secure 12Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?