IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  ISAM - Not getting Cookie after successful login.

    Posted Mon November 30, 2020 04:26 AM
    Edited by Mukesh Bhati Mon November 30, 2020 04:28 AM
    Hello All,

    I'm using the Out-Of-Box password policy, after successful login.

    it does not return cookies (PD-S-SESSION-ID).

    https://<host>/mga/sps/apiauthsvc?PolicyId=urn:ibm:security:authentication:asf:password

    can anyone help me?

    After Successful login, webSEAL doesn't return PD-S-SESSION-ID Cookie.


    ------------------------------
    Mukesh
    ------------------------------


  • 2.  RE: ISAM - Not getting Cookie after successful login.

    Posted Mon November 30, 2020 05:20 AM
    Hi Mukesh,

    Are you sending an OAuth bearer token with the requests you're making to the Reverse Proxy?  If you are then this will be used as the session handle and you won't receive a session cookie.  This is by design because, in most cases, API clients don't like to handle cookies.

    You can disable this behaviour by removing the "session = authorization" parameter from the configuration file but consider if that's really what you want to do.

    Jon.

    ------------------------------
    Jon Harry
    Consulting IT Security Specialist
    IBM
    ------------------------------



  • 3.  RE: ISAM - Not getting Cookie after successful login.

    Posted Mon November 30, 2020 08:06 AM
    Edited by Mukesh Bhati Mon November 30, 2020 08:09 AM
    Hi Jon,

    I'm not using the OAuth bearer token, data required for authentication is passed as JSON in the request body.






    ------------------------------
    Mukesh
    ------------------------------



  • 4.  RE: ISAM - Not getting Cookie after successful login.

    Posted Mon November 30, 2020 08:32 AM
    Hi Mukesh,

    What headers do you see in the reponse?  If you're seeing am-eai-* headers then that means the Reverse Proxy is not recognizing the responses from the AAC Authentication Service as login triggers.

    These triggers are usually set up when you run the wizard which configures the Reverse Proxy as the point-of-contact for the AAC Authentication Service.  You can see these triggers in the [eai-trigger-urls] configuration stanza.

    Jon.

    ------------------------------
    Jon Harry
    Consulting IT Security Specialist
    IBM
    ------------------------------



  • 5.  RE: ISAM - Not getting Cookie after successful login.

    Posted Tue December 01, 2020 03:02 AM
    Hi Jon,

    Thanks for the help!

    after setting eai-auth = https in webSeal configuration file.

    webSeal returns PD-S-SESSION-ID cookies.

    ------------------------------
    Mukesh
    ------------------------------