| Weblog Navigation |
| Secure Cookies in Horde (Wednesday, September 10th, 2008) |
|
There was some recent rumbling on Slashdot about secure cookies, and I decided to check my own webmail sites. Lo and behold, they weren't setting secure cookies. If you run Horde on HTTPS, you should configure Apache to make it completely inaccessible over HTTP. The simplest way of doing this is to set up a virtual host for HTTP that doesn't point to Horde, but instead does a redirect to the HTTPS site. For example:
Once that's taken care of, there's one more step: you need to configure Horde not to allow HTTP connections. This is safe, because you've already set up your web server not to allow HTTP connections anyway (any HTTP connections get redirected to HTTPS without touching Horde first). To do this, log
into Horde as an Administrator, and go to Horde Setup. Under “General
Horde Settings”, where it says
“ Hope this helps! |
| Weblog Navigation |
| Navigation |
| Themes |
| Random Quote |
|
“The Holocaust was an obscene period in our nation's history. I mean
in this century's history. But we all lived in this century. I didn't live
in this century.”
- Dan Quayle |