Page 1 of 1

Revisiting The Security Issue..

Posted: Thu Feb 13, 2020 3:31 pm
by Michale32086
A while back I had asked about error messages my employers have been getting on their credit card compliance scans..

They are:

Session Cookie Does Not Contain the "Secure" Attribute

HTTP Security Header Not Detected


Those errors are the ports that are running two separate BI system..

I talked my employer into upgrading to v5 of BI in hopes that it would fix the problem..

No such luck..

Any ideas????

Any help would be most appreciated..

Re: Revisiting The Security Issue..

Posted: Thu Feb 13, 2020 4:09 pm
by HeneryH
BI chose to use a proprietary web server of unknown source code origin. I kind of wish it was more clearly segregated into a module with nginx or apache.

On another rant...

When will we be able to let users set their own passwords???? I HATE having to create passwords for users and then tell them what it is.

Re: Revisiting The Security Issue..

Posted: Fri Feb 14, 2020 2:34 pm
by Michale32086
Thanx for the reply..

I have touched bases with BI SUPPORT.. Maybe they can issue a patch or something..

Thanx again...