What is FORMCRED cookie ?
search cancel

What is FORMCRED cookie ?

book

Article ID: 46283

calendar_today

Updated On:

Products

CA Single Sign On Secure Proxy Server (SiteMinder) CA Single Sign On SOA Security Manager (SiteMinder) CA Single Sign-On

Issue/Introduction

 

What is FORMCRED cookie ?

 

Environment

 

Web Agent : v6 and above

 

Resolution

 

On a POST to an FCC the FCC will generate several cookies. This includes the FORMSCRED cookie which is created when FCCCompatMode is set to the value YES. These cookies represent the old way of doing forms login and should be considered deprecated.    

The functionality only exists today to provide backward compatibility with older SiteMinder installations. The FORMCRED cookie is generated from the USERNAME and PASSWORD variables. In the default mode (FCCCOmpatMode="NO"), The FCC will log the user in directly and on successful authentication redirect the user back to the TARGET URL with a SMSESSION cookie using SSO instead of FORMCRED credentials to access the TARGET.

The FORMCRED cookie is further encrypted using Agent Keys.