Return-Path: Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: (qmail 35396 invoked from network); 27 Oct 2009 23:03:41 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.3) by minotaur.apache.org with SMTP; 27 Oct 2009 23:03:41 -0000 Received: (qmail 7593 invoked by uid 500); 27 Oct 2009 22:01:40 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 7545 invoked by uid 500); 27 Oct 2009 22:01:40 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 7533 invoked by uid 99); 27 Oct 2009 22:01:39 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 27 Oct 2009 22:01:39 +0000 X-ASF-Spam-Status: No, hits=-6.6 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: domain of rainer.jung@kippdata.de designates 195.227.30.149 as permitted sender) Received: from [195.227.30.149] (HELO mailserver.kippdata.de) (195.227.30.149) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 27 Oct 2009 22:01:37 +0000 Received: from [192.168.2.100] ([192.168.2.100]) by mailserver.kippdata.de (8.13.5/8.13.5) with ESMTP id n9RM1EIf021590 for ; Tue, 27 Oct 2009 23:01:15 +0100 (CET) Message-ID: <4AE76DAA.4080709@kippdata.de> Date: Tue, 27 Oct 2009 23:01:14 +0100 From: Rainer Jung User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.9.1.4pre) Gecko/20090915 Thunderbird/3.0b4 MIME-Version: 1.0 To: Tomcat Users List Subject: Re: SessionID cookie not secure over SSL References: <9533B907B006F745AAE94FAFD1C84C1CD306C3@EXCHANGE.helixmail.local> <4AE761D9.3010605@ice-sa.com> In-Reply-To: <4AE761D9.3010605@ice-sa.com> Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 8bit On 27.10.2009 22:10, Andr� Warnier wrote: > Joe Wallace wrote: >> >> -----Original Message----- >> From: Andr� Warnier [mailto:aw@ice-sa.com] >> Sent: Tuesday, October 27, 2009 4:48 PM >> To: Tomcat Users List >> Subject: Re: SessionID cookie not secure over SSL >> >> >>> Joe Wallace wrote: >>>> I am using session cookies to track sessions. I am used to Jrun >>>> where you would specifically set the cookie to be sent only over SSL >>>> or https. This was not the >default setting. I want users to >>>> connect to my web site using https then they might click a link on >>>> one of my web pages whose protocal is not secure. What is the >>>> >behavior of the JSESSIONID cookie in this situation. >>>> >>> Joe, >> >>> 1) assuming your setup is >> >>> browsers <--> IIS <--> Tomcat >> A B >> >>> which portion(s) is(/are) using HTTPS ? A ? B ? both ? >> >>> 2) "secure" is an attribute of a cookie, written inside of the cookie >>> by the server creating the cookie in the first place. >>> If set, it has as consequence that a browser will only send it back >>> to the original server with subsequent requests, if these subsequent >>> requests happen over a HTTPS connection. >> >>> In other words, if you set the secure attribute on the JSESSIONID >>> cookie, because for instance your initial request happens over HTTPS, >>> then you switch to a non-HTTPS part of the site, the browser is >>> probably no longer going to send this cookie back to the server. >>> In other words, you will, for practical purposes, "lose your session". >> >>> Not so, gurus ? >> >> Portion A is using IIS. IIS holds the SSL cert. >> I am using AJP 1.3 connector for IIS >> It is defined in the Tomcat Server.xml >> >> >> > /> >> > > Am I mistaken then to think that since the connection B from IIS to > Tomcat is not over HTTPS but over AJP, Tomcat has no idea that HTTPS is > being used ? It should know that. The AJP13 protocol transports the comunication situation observed by the web server to Tomcat which then provides it to the webapp by extracting it from the protocol in the AJP connector. See also http://tomcat.apache.org/connectors-doc/generic_howto/proxy.html Regards, Rainer --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org