PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

How to enable HTTP only flag for the cookies PS_LOGINLIST, PS_TOKENEXPIRE and ExpirePage in peopleso

edited Apr 23, 2020 7:12PM in PeopleTools and Lifecycle Management - PSFT (MOSC) 3 commentsAnswered

Hi ,

Please suggest how we can enable http only flag for the cookies PS_LOGINLIST, PS_TOKENEXPIRE, ExpirePage .. etc.

As per Oracle document id 985574.1, "E-PIA: Does PeopleSoft PIA Support HTTPOnly for Cookies?" , PS_TOKEN  cert cannot be set to HTTPOnly by design.

Just wanted to confirm whether HTTP only flag can be enabled for other session cookies like PS_LOGINLIST, PS_TOKENEXPIRE, ExpirePage ,HPTabName, HPTabNameRemote and SignOnDefault.

Http only flag is not enabled even after added <cookie-http-only> tag in weblogic.xml.

<cookie-http-only>true</cookie-http-only>

PeopleTools Release: 8.53.09

Oracle Weblogic 10.3.6.0.0

Thanks in advance for your suggestions.

Thanks,

Anbu G

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center