Symantec Access Management

Tech Tip : CA Single Sign-On : How do I prevent a cookie replay attack in Siteminder? 

Jul 31, 2018 04:39 AM

Question

 

How do I prevent a cookie replay attack in Siteminder?

 

 

Environment



Policy Server version: 12.52.X

 


Answer

 

 

Any application that manages sessions via cookie is subject to replay attacks. Siteminder has multiple embedded features that can help in preventing Cookie Replay.


1) Implement a Session Store

2) Configure your Realms to use the Session Store by configuring the Realm to use Persistent Sessions and by configuring the validation period setting.

3) Configure a Logoff URI. If set with Session Store. The Logoff URI will set the Cookie as LOGGEDEOFF in the session store and it can no longer be replayed.

Please find additional information regarding this issue.

"https://support.ca.com/cadocs/0/CA%20SiteMinder%2012%2052%20SP1-ENU/Bookshelf_Files/PDF/siteminder_wa_config_enu.pdf"

Chapter 8 page 108 (Store Session Cookies on the Session Store for Improved Security)

 

 

KD : KB000108653

Statistics
0 Favorited
1 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.