<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cookie Does Not Contain The ¨secure¨ Attribute in SaaS in Real User Monitoring</title>
    <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118070#M1774</link>
    <description>&lt;P&gt;Hi. &lt;/P&gt;&lt;P&gt;We are working with Dynatrace Saas, with &lt;STRONG&gt;OneAgent&lt;BR /&gt;version 1.157.201.20181211-092722&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The security department of our&lt;BR /&gt;company found a warning security risk.&lt;/P&gt;&lt;P&gt;Cookie Does Not Contain The&lt;BR /&gt;¨secure¨ Attribute&lt;/P&gt;&lt;P&gt;Impact: Cookies with “secure”&lt;BR /&gt;attribute are one permitted to be sent via HTTPS. Cookies sent via HTTP expose&lt;BR /&gt;an unsuspecting user to sniffing attacks that could lead to user impersonation&lt;BR /&gt;or compromise of the application account.&lt;/P&gt;&lt;P&gt;HTTP Cookie missing Secure&lt;BR /&gt;attribute on port 443.&lt;/P&gt;&lt;P&gt;Set-Cookie:&lt;BR /&gt;dtCookie==3=srv=3=sn=3A695446E5F92C0A76D24CFC824D60B4=perc=100000=ol=0=mul=1;&lt;BR /&gt;Path=/&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Could anybody please tell us&lt;BR /&gt;if there is an option we could configure to avoid this warning?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have seen something similar&lt;BR /&gt;but in AppMon &lt;/P&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 09 May 2019 22:09:15 GMT</pubDate>
    <dc:creator>porrasmj</dc:creator>
    <dc:date>2019-05-09T22:09:15Z</dc:date>
    <item>
      <title>Cookie Does Not Contain The ¨secure¨ Attribute in SaaS</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118070#M1774</link>
      <description>&lt;P&gt;Hi. &lt;/P&gt;&lt;P&gt;We are working with Dynatrace Saas, with &lt;STRONG&gt;OneAgent&lt;BR /&gt;version 1.157.201.20181211-092722&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The security department of our&lt;BR /&gt;company found a warning security risk.&lt;/P&gt;&lt;P&gt;Cookie Does Not Contain The&lt;BR /&gt;¨secure¨ Attribute&lt;/P&gt;&lt;P&gt;Impact: Cookies with “secure”&lt;BR /&gt;attribute are one permitted to be sent via HTTPS. Cookies sent via HTTP expose&lt;BR /&gt;an unsuspecting user to sniffing attacks that could lead to user impersonation&lt;BR /&gt;or compromise of the application account.&lt;/P&gt;&lt;P&gt;HTTP Cookie missing Secure&lt;BR /&gt;attribute on port 443.&lt;/P&gt;&lt;P&gt;Set-Cookie:&lt;BR /&gt;dtCookie==3=srv=3=sn=3A695446E5F92C0A76D24CFC824D60B4=perc=100000=ol=0=mul=1;&lt;BR /&gt;Path=/&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Could anybody please tell us&lt;BR /&gt;if there is an option we could configure to avoid this warning?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have seen something similar&lt;BR /&gt;but in AppMon &lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 09 May 2019 22:09:15 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118070#M1774</guid>
      <dc:creator>porrasmj</dc:creator>
      <dc:date>2019-05-09T22:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cookie Does Not Contain The ¨secure¨ Attribute in SaaS</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118071#M1775</link>
      <description>&lt;P&gt;Go to Application settings =&amp;gt; Advanced:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.dynatrace.com/legacyfs/online/20478-zrzut-ekranu-2019-05-10-o-085602.png" /&gt;&lt;/P&gt;&lt;P&gt;Here is option you need.&lt;/P&gt;&lt;P&gt;Sebastian &lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 10 May 2019 06:56:40 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118071#M1775</guid>
      <dc:creator>skrystosik</dc:creator>
      <dc:date>2019-05-10T06:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cookie Does Not Contain The ¨secure¨ Attribute in SaaS</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118072#M1776</link>
      <description>&lt;P&gt;We already set the set the attibute to our application but the the result scan still says the cookie is not secured.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.dynatrace.com/legacyfs/online/20628-dtcookienotsecured.jpg" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please anwser the two questions:&lt;/P&gt;
&lt;P&gt;Q1. Is there any something else we should configure? Maybe in the two host of our dmz cluster?&lt;/P&gt;
&lt;P&gt;Q2. Our two dmz host have the latest available version : OneAgent version 1.167.176.20190508-104947, however, the &lt;STRONG&gt;&lt;U&gt;Cookie and header settings&lt;/U&gt;&lt;/STRONG&gt; requires OneAgent version 1.87 or highter&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.dynatrace.com/legacyfs/online/20629-cookiechecksetted.jpg" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;but&lt;/U&gt;&lt;/STRONG&gt; the point is the latest version available for us is 1.167....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I think something is wrong: or the label which ask 1.87 version or why we only can see until 1.167 version...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:30:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118072#M1776</guid>
      <dc:creator>porrasmj</dc:creator>
      <dc:date>2021-11-26T14:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cookie Does Not Contain The ¨secure¨ Attribute in SaaS</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118073#M1777</link>
      <description>&lt;P&gt;1.167 is grater version than 1.87 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; If after reconfiguration cookie is still unsecure make sure that this applications covers all requests that you are talking about. If you have more than one application or there are some requests in default one it is possible that there are some of them without secure parameter. If not, open support ticket and put link to this questions.&lt;/P&gt;&lt;P&gt;Sebastian &lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 23 May 2019 18:30:27 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Cookie-Does-Not-Contain-The-secure-Attribute-in-SaaS/m-p/118073#M1777</guid>
      <dc:creator>skrystosik</dc:creator>
      <dc:date>2019-05-23T18:30:27Z</dc:date>
    </item>
  </channel>
</rss>

