11503 Content Switch and SSL Termination - Cookie Handling

Oct 11, 2006 1 Replies

I'm looking for some insight on how the 11503 handles SSL termination, specifically with regard to cookie handling. We are going to be installing a 11503, so it can handle load balancing, content switching and SSL termination instead of IIS / WLBS. If you move SSL termination off of the Web servers and disable SSL in IIS, how does ASP.NET handle secure cookies? We want to set requireSSL="true" in Web.config, but since the Web server will no longer be running SSL, it won't enforce that attribute. I was wondering if the content switch passed any special header to IIS, or if the content switch can be configured to add the secure attribute to all cookies. I haven't found anything in the documentation so far.


Thanks!



I'm looking for some insight on how the 11503 handles SSL termination, specifically with regard to cookie handling. We are going to be installing a 11503, so it can handle load balancing, content switching and SSL termination instead of IIS / WLBS. If you move SSL termination off of the Web servers and disable SSL in IIS, how does ASP.NET handle secure cookies? We want to set requireSSL="true" in Web.config, but since the Web server will no longer be running SSL, it won't enforce that attribute. I was wondering if the content switch passed any special header to IIS, or if the content switch can be configured to add the secure attribute to all cookies. I haven't found anything in the documentation so far.

Thanks!

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required