Securing HTTP Cookies Created by App Portal
If your App Portal website is running under HTTPS binding (https:// is visible in the URL), then you need to make a configuration change so that HTTP cookies will only be transmitted under HTTPS communication.
To secure HTTP cookies created by App Portal:
- Locate the following file on your App Portal Website server:
[App Portal Installation Location]\web\web.config
- Open the web.configfile (as an Administrator) in a text editor.
- In the  <httpCookies>element, change the value of therequireSSLparameter fromfalsetotrue:
<httpCookies httpOnlyCookies="true" requireSSL="true" />
info
If your organization is using HTTP binding (http:// is visible in the URL), then the requireSSL parameter must remain set to false.