Security Guide for Siebel eBusiness Applications > Communications and Data Encryption > Configuring for Encryption >

Configuring Web Clients for Encryption


To use encryption, both the server and the client must enforce encryption in their connection parameters. If these parameters do not match, connection errors will occur.

Siebel eBusiness Applications support the following types of clients:

For more information about the first three clients listed above, see Siebel Web Client Administration Guide.

About Session Cookies

The Application Object Manager in the Siebel Server communicates with the Siebel Web Client through the Web server using TCP/IP protocol. An independent session is established to serve incoming connection requests from each client. Siebel applications use session cookies to track the session state.

These session cookies persist only within the browser session and are deleted when the browser exits or the user logs off. A session cookie attaches requests and logoff operations to the user session which started at the login page.

Instead of storing the session ID in clear text in the client's browser, Siebel applications create an encrypted session ID and attach an encryption key index to the encrypted session ID. Session cookie encryption is based on the RSA BSAFE Crypto standard and uses a 56-bit key default.

In Siebel Remote, the encryption algorithm and key exchange are the same as session-based components.

Session cookie encryption prevents session spoofing (deriving a valid session ID from an invalid session ID).

For more information about session cookies, refer to Siebel Web Client Administration Guide.


 Security Guide for Siebel eBusiness Applications 
 Published: 23 June 2003