Server Configuration Editor
The Server Configuration Editor enables you to update the following parameters when you install or configure the BMC Atrium Single Sign-On server:
General tab
Certificates tab
HTTP Only and HTTPS Only
With the release of BMC Atrium Single Sign-On 8.1 Patch 3, the Server Configuration Editor provides two new options: HTTP Only and HTTPS Only.
The HTTP Only parameter marks the BMC Atrium Single Sign-On cookie to prevent non-HTTP APIs such as JavaScript from accessing the cookie. When enabled, the HTTPS Only parameter marks the cookie with the Secure option, which ensures that the cookie is transmitted only over HTTPS connections from the browser to the server.
The default value of these check boxes is false. When set to true, these options prevent scripts and third-party programs from accessing the cookies.
To secure BMC Atrium Single Sign-On as a stand-alone server
- Open the Edit Server Configuration tab on the BMC Atrium SSO Admin Console.
- Select the HTTP Only and HTTPS Only check boxes, and click Save.
- Restart the BMC Atrium Single Sign-On server.
- Clear all cookies from the browser history.
To secure BMC Atrium Single Sign-On as a High Availability cluster
- Open the HA Node Details tab on the BMC Atrium SSO Admin Console.
- Select the node for which the HTTP Only and HTTPS Only options are to be enabled.
Select the HTTP Only and HTTPS Only check boxes for each node, and click Save.
- Restart the server.
- Clear all cookies from the browser history.