Forum Discussion
hooleylist
Mar 23, 2011Cirrostratus
I submitted an internal request to add a checkbox option to the cookie insert persistence profile for encryption and an encryption passphrase to make it very clear that you can encrypt the cookie value and simple to do so.
Hamish, I can see both sides of your request. From a security standpoint, I think it's a good practice to limit the amount of information you give potential attackers. But I think the actual security risk is fairly low and the performance hit for the encryption is not nothing.
Anyhow, if you'd like to see such a feature added in a future version, you can open a case with F5 Support and request this change. If you get a RFE ID, please reply back here with it for others to reference.
Thanks, Aaron