Defining SAP Logon Tickets as Secure Cookies 

Use

If a cookie is marked secure, it is only transmitted if the communications channel with the host is a secure one. Currently this means that secure cookies are only sent to HTTPS servers. If a cookie is not marked secure, it is considered safe to be sent in unencrypted form over unsecured channels.

In the Enterprise Portal you can configure SAP logon tickets as secure cookies. Then they will only be sent to HTTPS servers. This is a way of ‘forcing’ secure connections between the browser and servers.

Procedure

  1. Open the usermanagement.properties file and add the following line:
  2. login.ticket_secure=true

    (If you do not want the SAP logon ticket to be secure, either comment out the property or set it to ‘0’).

  3. Save your changes.
  4. Restart the Java servlet engine.