Legacy Knowledge Base
Published Jul. 2, 2025

JSESSIONID not secure by default

Written By

Christopher Czibere

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

Legacy Article

You are viewing an article from our legacy "FastTrack" publication program, made available for informational purposes. Articles in this program were published without a requirement for independent editing or verification and are provided"as is" without guarantee.

Before using any information from this article, independently verify its suitability for your situation and project.

Issue

  • The JSESSIONID cookie that comes with Liferay requests in the browser is not secure by default when inspected in the browser.

Environment

  • Liferay DXP 7.3

Resolution

  • Set the JSESSIONID in web.xml to secure:
<session-config>
    <cookie-config>
        <http-only>true</http-only>
        <secure>true</secure>
    </cookie-config>
 </session-config>

Additional Information

  • The JSESSIONID is generated by the Application server and should be set there as secure when you access the App server through HTTPS instead of HTTP because cookies can only be marked as secure when using the HTTPS protocol

  • If the access to the app server didn't go through HTTPS, this configuration is not generated and then needs to be set later in the web.xml. So this is not enabled by default.

Did this article resolve your issue ?

Legacy Knowledge Base