Previous Topic: How to Configure Single Sign-On

Next Topic: Set Persistent Cookies

Require Cookies for Basic Authentication

You can control whether or not SiteMinder requires cookies with the following parameter:

RequireCookies is a special setting that is useful only if basic authentication was set during the Policy Server configuration. This setting instructs the agent to require either an SMSESSION or an SMCHALLENGE cookie in order to successfully process HTTP requests, including basic Authorization headers.

If the Web Agent does not require cookies, but the user's Web browser is accepting cookies, the Web Agent functions normally; however, the user may be challenged for credentials unexpectedly and the Web Agent may not strictly enforce time-outs.

To require cookies, set the RequireCookies parameter to yes.


Copyright © 2010 CA. All rights reserved. Email CA about this topic