SAP Knowledge Base Article - Preview

2055737 - Missing Secure Attribute in SSL for Cookie PortalAlias

Symptom

  • You have configured SSL for your portal URL.
  • PortalAlias cookie doesn't set securely, see following red part: 
    GET /irj/portal HTTP/1.1
    Cookie:
    com.sap.engine.security.authentication.original_application_url=GET#ugazYPebPlpReANFCN3arra0G7o%2
    F%2FZO71YDdcrIX4kKZaXxg5OEuzkxr1YuWfAbyzhDN6phDmxjVFyrIO2IQInwHjNH%2B3c6OwZy9f4fXIV4%3D; saplb_*=
    (J2EEXXXXXXXX)XXXXXX; PortalAlias=portal
    Accept-Language: en-US
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
    Host: XXXXXXXX
    User-Agent: XXXXXX
    HTTP/1.1 200 OK
    server: SAP NetWeaver Application Server XXXX
    content-type: text/html; charset=UTF-8
    pragma: no-cache
    cache-control: no-cache
    expires: 0
    date: XXXXXXXXXX
    transfer-encoding: chunked
    Set-Cookie: PortalAlias=portal; Path=/


Read more...

Environment

  • EP Release Independent
  • SAP NetWeaver
  • SAP Composition Environment

Product

SAP NetWeaver 2004 ; SAP NetWeaver 7.0 ; SAP NetWeaver 7.3 ; SAP NetWeaver 7.4 ; SAP NetWeaver 7.5 ; SAP NetWeaver Composition Environment 7.1 ; SAP NetWeaver Composition Environment 7.2 ; SAP enhancement package 1 for SAP NetWeaver 7.0 ; SAP enhancement package 1 for SAP NetWeaver 7.3 ; SAP enhancement package 1 for SAP NetWeaver Composition Environment 7.1 ; SAP enhancement package 2 for SAP NetWeaver 7.0 ; SAP enhancement package 3 for SAP NetWeaver 7.0

Keywords

portal.alias.security.enforce_secure_cookie, AliasService , KBA , EP-PIN , SAP Enterprise Portal (On Premise) , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.