Re: Cookie security for nginx

2017-10-10 Thread Johann Spies
> This is something you should fix on whatever application is setting the > cookie. It probably isn't nginx. > Thanks. That helped. Regards Johann -- Johann SpiesTelefoon: 021-808 4699 Databestuurder / Data manager Faks: 021-883 3691 Sentrum vir Navorsin

Re: Cookie security for nginx

2017-10-10 Thread Richard Stanway via nginx
This is something you should fix on whatever application is setting the cookie. It probably isn't nginx. On Tue, Oct 10, 2017 at 10:04 AM, Johann Spies wrote: > A security scan on our server showed : > > Vulnerability Detection Method > Details: SSL/TLS: > Missing `secure` Cookie Attribute > OID