[viewvc-users] how would I configure Apache to force cookies to be secure?
Notice Sender <[email protected]>
| Newsgroups | gmane.comp.version-control.cvs.viewcvs.user |
|---|---|
| Message-ID | <AANLkTinBYGy8YkJSq64Bgwx2uGz4Ur+s6tRXZbBLt7Sg__53.8707747638867$1283894370$gmane$org@mail.gmail.com> |
Hi, Does anyone know how to configure Apache to force ViewVC's cookies to be secure? Right now, my understanding is that any server between the browser and the ViewVC server can steal the cookie and impersonate the logged-in user. I think the typical way of handing this is to set cookies to be secure (e.g. for PHP, it's setting session.cookie_secure=1). Does anyone know the Apache counterpart for ViewVC? (I'm guessing it's a RewriteRule, but am not sure.) Thanks, Jerry ------------------------------------------------------ http://viewvc.tigris.org/ds/viewMessage.do?dsForumId=4255&dsMessageId=2656586 To unsubscribe from this discussion, e-mail: [[email protected]].