Skip to main content
 
developerWorks
AIX and UNIX
Information Mgmt
Lotus
New to Lotus
Products
How to buy
Downloads
Live demos
Technical library
Training
Support
Forums & community
Events
Rational
Tivoli
WebSphere
Java™ technology
Linux
Open source
SOA and Web services
Web development
XML
My developerWorks
About dW
Submit content
Feedback



developerWorks  >  Lotus  >  Forums & community  >  IBM Sametime Forum

IBM Sametime Forum

developerWorks

  

Sign in to participate PreviousPrevious NextNext


Dan Kinder 31.Mar.11 05:38 PM a Web browser
Applications development All Releases All Platforms


We have a Domino Application that has session authentication turned on. After running AppScan (with Policy Tester 8.0.0.2) against the application via the QuickScan Portal, we have a High severity issue that states "SESSION IDENTIFIER NOT UPDATED". the remediation task is "Do not accept externally created session identifiers". The post includes the following which is the item being flagged: "Set-Cookie: DomAuthSessId=204D8AD866DECB88C7251027B2361C77;"
I think the reason is that a potential hacker could attempt to steal the cookie/session id and therefore the user's credentials.

The application code that we have does not control the session or session ID, yet the scan is reporting that the way Domino handles the session is a security vulnerability.

After looking into the issue, it appears that with authentication turned on, Domino authenticates the first request with a username and password, then just uses a session ID, stored in a cookie to verify the users credentials.

So, my question...
Is this a behavior that I can control via a configuration change or is this just the way Domino handles authentication and the Session Identifiers? I need some documentation that verifies that this is Domino Product related and not code related so we can get an exception for this issue. If there is some way to change the configuration, then I need to make that change and re-scan the app.

Thank you for any help in getting this verified...








  Document options
Print this pagePrint this page

 Search this forum

  Forum views and search
Date (threaded)
Date (flat)
With excerpt
Author
Category
Platform
Release
Advanced search

 Sign In or Register
Sign in
Forgot your password?
Forgot your user name?
Create new registration

 RSS feedsRSS
All forum posts RSS
All main topics RSS
More Lotus RSS feeds

Resources

 Resources
Forum use and etiquette
Native Notes Access
Web site Feedback

Lotus Support

 Lotus Support
IBM Support Portal - Lotus software
Lotus Support documents
Lotus support by product
Lotus support downloads
Lotus support RSS feeds

Wikis

 Wikis
IBM Composite Applications
IBM Mashup Center
IBM Connections
IBM Docs
IBM Forms
IBM Mobile Connect
IBM Sametime
IBM SmartCloud for Social Business
IBM Web Experience Factory
Lotus Domino
Lotus Domino Designer
Lotus Expeditor
Lotus Foundations
Lotus iNotes
Lotus Instructor Community Courseware
Lotus Notes
Lotus Notes & Domino Application Development
Lotus Notes Traveler
Lotus Protector
Lotus Quickr
Lotus Symphony
IBM Web Content Manager
WebSphere Portal

Lotus Forums


 Lotus Forums
Notes/Domino 9.0
Notes/Domino 8.5 + Traveler
Notes/Domino XPages development forum
Notes/Domino 8
Notes/Domino 6 and 7
Notes/Domino 4 and 5
IBM Connections
IBM Forms
IBM Mobile Connect
IBM Sametime
IBM SmartCloud Notes
IBM SmartCloud Meetings
IBM Web Content Manager
Lotus Domino Document Manager
Lotus e-learning
Lotus Enterprise Integration
Lotus Expeditor
Lotus Protector
Lotus Quickr
Lotus SmartSuite
Lotus Symphony
Lotus Symphony Developer Toolkit Support
Lotus Workflow