Technology Blogs by Members
Explore a vibrant mix of technical expertise, industry insights, and tech buzz in member blogs covering SAP products, technology, and events. Get in the mix!
cancel
Showing results for 
Search instead for 
Did you mean: 
dharmdhwaj_singh
Explorer
0 Kudos

The MYSAPSSO2 cookie, also known as the logon ticket, is utilized in SAP systems to manage and authenticate user sessions across SAP's applications. It contains the username, SID, expiry attribute, and is encoded in base64 ensuring secure transmission of session information.

The expiry attribute of a cookie determines the duration it remains active in the user's browser before being automatically deleted. For the MYSAPSSO2 cookie, with a default expiration time of 8 hours, this attribute is vital for both security and usability. By setting an expiry date, the authentication information within the cookie is not left indefinitely accessible, thus mitigating the risk of unauthorized access in the event of a system compromise. The duration before expiration of the MYSAPSSO2 cookie can be adjusted according to an organization's security policies.

Microsoft discontinued support for Internet Explorer 11 on many versions of Windows 10 as of June 15, 2022. While IE mode in Edge is intended to provide a bridge for legacy application compatibility, organizations are encouraged to update web applications for compatibility with modern web standards and browsers. Nonetheless, many organizations continue to use IE11 mode due to dependencies on custom legacy applications developed both within and outside SAP systems.

By default, the Microsoft Edge and Internet Explorer processes don't share session cookies, and this lack of sharing can break Single Sign-on mechanism. Microsoft does provide a solution, i.e., by maintaining Enterprise Mode site list XML, to configure session cookie sharing between a Microsoft Edge process and an Internet Explorer process while using Internet Explorer mode. https://learn.microsoft.com/en-us/deployedge/edge-ie-mode-add-guidance-cookieshare

However, this feature does not support Persistent cookies, which have been created with an Expires attribute. The MYSAPSSO2 cookie, by design, includes an expiry attribute therefore, this feature will not work where logon ticket based SSO is used.  In scenarios where the MYSAPSSO2 cookie is used for SSO, it's recommended to use a single browser mode only. Please do note that  SAP advises transitioning from this legacy type of SSO to more secure mechanisms (e.g., SAML2, SPNEGO, X.509 certificates) as referenced in SAP note 3225900.

Labels in this area