PEGA-SESSION-COOKIE Secure

Hi all,

We have a request from our client security team to set the PEGA-SESSION-COOKIE as secure.

We have Pega Platform 25.1.2 in Pega Cloud.

We have created DSS prconfig/HTTP/SetSecureCookie/default , set its value to true and restarted the environment, but we keep seeing the cookie without the secure attribute checked.

I’ve noticed that the DSS has been created in lower case : prconfig/http/setsecurecookie/default . Could this have any impact?

I’d really appreciated any help on this.

Thanks in advance

What is the Owning Ruleset? Maybe this is root cause?

Have all nodes been restarted? Can you check SetCookie header on respone?

Take a look also here: https://support.pega.com/comment/1039656

The Owning ruleset is Pega-Engine and all nodes were restarted