IBM Support

WHICH ALGORITHM IS USED TO ENCRYPT FAILOVER COOKIES ON ISAM 9?

Product Documentation


Abstract

Starting with ISAM 8 keys used for failover cookies (PD-ID),
cross-domain SSO (cdsso), and E-Community SSO (e-community-sso)
are encrypted by default with AES-256.

Content

Starting with ISAM 8 keys used for failover cookies (PD-ID),
cross-domain SSO (cdsso), and E-Community SSO (e-community-sso)
are encrypted by default with AES-256.

There are configuration options that can change the encryption
used from AES-256 to DES for compatibility with older releases.
The parameters are:

# Version 4.1.0 has increased the security of these. However,
#it is not backward compatible. If you are
# integrating with earlier web servers you will need to enable
#this.
pre-410-compatible-tokens = no
# Version 8.0.0 tokens use a different cipher than tokens in
#prior releases.
# If you are integrating with earlier versions of ISAM you will
#need to enable
# this to ensure the integrity of data across
#[e-community-sso], [failover], and
# [cdsso].
pre-800-compatible-tokens = no

[{"Product":{"code":"SSZU8Q","label":"IBM Security Access Manager"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Web","Platform":[{"code":"PF025","label":"Platform Independent"},{"code":"PF004","label":"Appliance"}],"Version":"8.0.0;9.0.0","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
17 June 2018

UID

swg27051167