CA Single Sign On Secure Proxy Server (SiteMinder)CA Single Sign On SOA Security Manager (SiteMinder)CA Single Sign-OnCA Single Sign On Agents (SiteMinder)SITEMINDERCA Single Sign On Federation (SiteMinder)
Issue/Introduction
How to prevent a cookie replay attack in Siteminder?
Environment
Policy Server Version: All Supported Versions
Resolution
Any application that manages sessions via the cookie is subject to replay attacks. Siteminder has multiple embedded features that can help in preventing Cookie Replay.
Implement a Session Store;
Configure your Realms to use the Session Store by configuring the Realm to use Persistent Sessions and by configuring the validation period setting;
Configure a Logoff URI. If set with Session Store. The Logoff URI will set the Cookie as LOGGEDEOFF in the session store and it can no longer be replayed;
Implement IP Checking (Enable or disable IP checking with persistent and transient cookies):
Compare IP Addresses to Prevent Security Breaches (1);
Use the Session Store to Increase Security for Multi-Domain Single Sign-On (2)(3).