Ask a Question related to ASP, Design and Development.

  1. #1

    Default SSL, P3P & Cookies.

    Please oh please oh please can someone with some P3P knowledge help me out?

    I'm aware that this isn't strictly an ASP or IIS issue but the SSL groups
    listed on my news server appear abandoned and since I've been coming to
    these groups I'm sure I've seen many people ask and answer SSL related
    questions. So here goes:

    I've recently had a shared SSL enabled for my site to use, but am having
    enormous difficulty in incorporating it into my program.
    Having found that IE was blocking my cookies, I set about creating a P3P
    compatible privacy policy using the IBM policy creator
    ([url]http://www.alphaworks.ibm.com/tech/p3peditor[/url]). Uploaded the generated
    policy and associated written documents to the unsecure area of my website.
    Linked the policy to my data gathering page with a <LINK rel="P3Pv1"
    href=http://etc../p3p.xml>. Got a Compact Policy, haven't a clue what to do
    with it :(
    The results are not satisfactory.

    Page in SSL location loads, attempts to use Session variables, which I
    assume attempts to store a temporary cookie. IE shows an eye and no-entry
    sign privacy report. Privacy report says that one or more cookies was
    blocked and names it. Summary report gets the relevant P3P policy (i think).
    The policy includes methods that i thought would enable cookie usage:
    Policy 1 contains a <STATEMENT> tag specifying:
    <DATA-GROUP>
    <DATA ref="#dynamic.cookies"><CATEGORIES><state/></CATEGORIES></DATA>
    </DATA GROUP>

    and P3P.xml (located in root of non-secure url, pointed at by page in secure
    url.) contains a <POLICY-REFERENCES> tag specifying:
    <POLICY-REF about="policy1.xml">
    <INCLUDE>/*</INCLUDE>
    <COOKIE-INCLUDE/>
    </POLICY-REF>
    also tried specifying <COOKIE-INCLUDE name="*" value="*" domain="*"
    path="*"/>
    Result: No change. Tried all kinds of things with that CP string. No
    noticable changes so shan't list attempts. If you know how to use it (in
    html or asp) please advise me.

    Does anyone know how to make my site use its cookies? !!!

    Many thanks to anyone who tries ;)

    Matt Smith


    Matt Smith Guest

  2. Similar Questions and Discussions

    1. Cookies in FMS
      In my application Flash Media Server 2 makes HTTP requests to retrieve configuration data. Page that is requestet sets some cookies. I was very...
    2. Help with cookies
      I'm having trouble accessing my cookies after they're set. If I do a response.write on the cookie value immediately after it's set in code, it...
    3. php cookies
      Is it possible to set php cookies to delete after a period of user inactivity &amp; if so how?
    4. PHP and cookies
      ok I have a question maybe this might help if you have $_COOKIE that is a session cookie in path '/' you also have a cookie $_COOKIE that is a...
    5. cookies under php 4.06
      okay, i know this is stupid, and i'm gonna kick myself when someone points out the obvious... i've just put a site online, and found the server's...
  3. #2

    Default Re: SSL, P3P & Cookies.

    For anyone reading this and thinking "That's my problem too. Why did no one
    answer him and was it ever solved?"

    That CP string I didn't know what to do with gets put in an HTTP header.
    (Fair enough. Everyone tells you that.)

    Response.AddHeader "P3P", """CP=put that cp string here""
    policyref=""http://www.location of p3p.xml"""

    <POLICY-REF about="policy1.xml">
    Needs a # indicated reference to
    <POLICY name="Policy_Name" etc>
    in Policy1.xml
    e.g
    <POLICY-REF about="policy1.xml#Policy_Name">
    Thanks to the P3P validator for it's most unhelpful error messages on that.

    Most importantly:
    I.E 6 blocks cookies that are considered 'unsatisfactory'. Basically this
    means "where the purpose/recipient token does not contain the optional
    attribute, "i" or "o." "
    ([url]http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnpriv/htm[/url]
    l/ie6privacyfeature.asp). This document is the pitfall. If you're
    experiencing troubles like this with IE. Read it carefully.

    Matt Smith
    P.S I'm off to model some voodoo dolls of W3C promoters and stick them on
    the barbeque.


    Matt Smith Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139