Question
data:image/s3,"s3://crabby-images/a87f0/a87f09768d8f37a6baf4d059ebafe624620a166f" alt=""
Evonsys (PVT) LTD
LK
Last activity: 25 Feb 2025 6:00 EST
How to Enforce Secure Cookies in Pega?
Hi Team,
I’m working on securing cookies in Pega and facing the issue of "Missing Secure Flag". I understand that without the Secure flag, cookies might be transmitted over HTTP instead of HTTPS, making them vulnerable to interception.
Here are the steps I’m considering:
-
Enable Secure Cookies in DSS (Dynamic System Settings):
- Owning Ruleset:
Pega-Engine
- Setting Purpose:
http/secureCookies
- Value:
true
- Owning Ruleset:
-
Update
prconfig.xml
:- Add:
<env name="http/secureCookies" value="true" />
- Add:
After applying these changes, I also plan to verify the cookies in Chrome DevTools to confirm the Secure flag is set.
Has anyone implemented this in their Pega environment? Are there any additional considerations or steps I should take to ensure that the Secure flag is properly enforced?
Thanks in advance for your help!
Eranda.