IBM Support

PI46616: Allow RewriteRule to use colon (':') in header names and values

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Cookies that contain colon (:) in the name or value can't be
    set by RewriteRule since that character is the default
    separator, and an alternate separator can't be used.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM HTTP Server users of RewriteRule for    *
    *                  setting cookies.                            *
    ****************************************************************
    * PROBLEM DESCRIPTION: Can't use RewriteRule to set cookies    *
    *                      that contain colon (:) in the name or   *
    *                      value.                                  *
    ****************************************************************
    * RECOMMENDATION:  Apply this fix if using RewriteRule to set  *
    *                  cookies.                                    *
    ****************************************************************
    In IBM HTTP Server, when using RewriteRule to set a cookie,
    the normal separator is colon (:) but this does not work for
    cookies that contain colon (:) in the name or value.
    This fix will allow IBM HTTP Server to use semi-colon (;) as
    the cookie separator in the RewriteRule instead.
    

Problem conclusion

  • This fix to allow semi-colon (;) as the cookie separator
    requires an opt-in new syntax to use the alternate semi-colon
    separator:
    
      [CO=;FOO:BAR;BAZ;example.com]
          ^ first character must be ; to use ; as a later separator
                  ^ separator
                      ^ separator
    
    In the example above, the cookie name contains a colon, so a
    semi-colon is used as the cookie separator instead.
    
    This fix is targeted for IBM HTTP Server fix packs:
    - 7.0.0.41
    - 8.0.0.12
    - 8.5.5.8
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI46616

  • Reported component name

    IBM HTTP SERVER

  • Reported component ID

    5724J0801

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2015-08-10

  • Closed date

    2015-09-23

  • Last modified date

    2015-09-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM HTTP SERVER

  • Fixed component ID

    5724J0801

Applicable component levels

  • R700 PSY

       UP

  • R800 PSY

       UP

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTJ","label":"IBM HTTP Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
07 September 2022