[viewvc-users] how would I configure Apache to force cookies to be secure?

Notice Sender <[email protected]>
Newsgroups gmane.comp.version-control.cvs.viewcvs.user
Message-ID <AANLkTinBYGy8YkJSq64Bgwx2uGz4Ur+s6tRXZbBLt7Sg__53.8707747638867$1283894370$gmane$org@mail.gmail.com>
Hi,

Does anyone know how to configure Apache to force ViewVC's cookies to be
secure?

Right now, my understanding is that any server between the browser and the
ViewVC server can steal the cookie and impersonate the logged-in user. I
think the typical way of handing this is to set cookies to be secure (e.g.
for PHP, it's setting session.cookie_secure=1). Does anyone know the Apache
counterpart for ViewVC? (I'm guessing it's a RewriteRule, but am not sure.)

Thanks,
Jerry

------------------------------------------------------
http://viewvc.tigris.org/ds/viewMessage.do?dsForumId=4255&dsMessageId=2656586

To unsubscribe from this discussion, e-mail: [[email protected]].
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.