[ic] 4.7.x SSL domain problem...

interchange-users@lists.akopia.com interchange-users@lists.akopia.com
Sun Jun 3 17:16:53 2001


On Sun, Jun 03, 2001 at 02:43:17PM -0600, John Beima wrote:
> G'Day Folks,
> 
> I have a little one some of you folks might find chalanging...
> 
> With 4.0x and 4.6.x crossing domains for SSL seemed to work fine, via posting
> forms...
> 
> However with 4.7.x you loose your session entirely...
> 
> Just a little background...
> 
> Catalog URL:  www.store.com
> SSL URL:  secure.isp.com
> 
> Since the domains are changing, when you enter the secure pages Interchange is
> issuing a new session number, as opposed to parsing it from the URL. It basicly
> is looking it up in the stored cookie instead of the cgi url... Which of course
> when you are at the new domain you can't read cookies out on by the old domain.
> 
> I have tried:
> 
> #01:
> 
> CookieDomain .store.com
> 
> #2:
> 
> CookieDomain .store.com .isp.com
> 
> #3:
> 
> CookieDomain .store.com
> CookieDomain .isp.com
> 
> #4:
> 
> Cookies No
> 
> All in the after.cfg file... None of the above works...
> 
> Any ideas???


You should not be able to use cookies cross domain.  Put the
sessionID in your form.  Or just buy a cert for your domain.



> 
> 
> 
> John Beima
> jbeima@palb.com, support@alocalagent.com, and support@alocalchurch.com
> 
> P.A.L.B. Systems - Phone: (780)451-1086 - Fax: (780)447-4760
> 11639-122 Street, Edmonton, Alberta, Canada, T5M 0B6
> 
> Affordable Web Pages - Phone: (888)932-9990 - Fax: (256)351-7297
> 2713B Spring Place SW, Decatur, Alabama, United States, 35603
> _______________________________________________
> Interchange-users mailing list
> Interchange-users@lists.akopia.com
> http://lists.akopia.com/mailman/listinfo/interchange-users

-- 

Christopher F. Miller, Publisher                             cfm@maine.com
MaineStreet Communications, Inc         208 Portland Road, Gray, ME  04039
1.207.657.5078                                       http://www.maine.com/
Content management, electronic commerce, internet integration, Debian linux