kentico_jurajo
-
9/7/2013 1:31:42 AM
RE:How to secure ASP.NET_SessionId
Hello,
Could you please describe the issue in details? I am unable to reproduce it.
I have set my IIS to use SSL certificate as well as the entire web site in my Kentico is set to use SSL. I have secured the session cookie as mentioned in this thread - using the requires SSL for Forms tag as well as for the httpCookies tag. Cleared all the cache and history in the browser and visited the site. After I logged it, session cookie is encrypted. Then I logged out and requested password reset. I have copied the link from the e-mail (since I am using local SMTP Server) and pasted it to the browser. The reset password page is loaded (https) and I am able to reset the password just fine. Am I missing something?
Best regards, Juraj Ondrus
|