cancel
Showing results for 
Search instead for 
Did you mean: 

Impact of turning off cookies in Standalone ITS

Former Member
0 Kudos

Hi All,

We are using Stand-alone ITS 6.20 patch 19 along with EP6 and IBM TAM/WebSEAL 5.1 as a single sign-on reverse proxy. We have encountered a scenario whereby we may need to turn off cookies in the ITS (~cookies 0) because of an issue with WebSEAL handling cookies.

Does anyone know what the impact is of turning off cookies? Because the cookies in question relation to session management, I would presume that ITS session management is degraded, and consequently performance is impacted? I have looked in the ITS documentation however and cannot find anything meaningful about the impacts.

Any contributions would be greatly appreciated and rewarded.

Thanks

John Moy

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

U can turned off Ur cookies in the GLOBAL.SRV file.

Former Member
0 Kudos

Thanks,

I realise that we can turn off cookies. I am wanting to know however what is the underlying IMPACT of doing this?

Former Member
0 Kudos

Hi John

when SSO is turned on,the ITS always expects the SSO initiater system to take care of the ITS session management.

Infact inorder for SAP SSO (which in turn uses extensive cookie) to work properly, the ITS cookie creation has to be truned off.

hope this helps.

-Dhruv

Former Member
0 Kudos

Thanks for the response.

Please bear in mind that we are using IBM WebSEAL as the SSO mechanism, which acts as a reverse proxy. We found that the cookies are being sent to this WebSEAL server, but that it was not handling multiple simultaneous cookies (one would overwrite the other). In the end the WebSEAL guys solved by applying a hotfixpack to WebSEAL, which implies that this behaviour of losing cookies was a WebSEAL bug. Therefore, we no longer need to turn off cookies at the ITS level, and all is good!