<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense: SameSite doesn't work with insecure sites (HTTP) in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-SameSite-doesn-t-work-with-insecure-sites-HTTP/ta-p/1758476</link>
    <description>&lt;P&gt;In Qlik Sense, when enabling the SameSite attribute and HasSecure attributes for a non-secure site (&lt;FONT face="courier new,courier"&gt;http://&lt;/FONT&gt;), the browser still refuses to set up the cookie.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Environments:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise for Windows November 2018 and later&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the SameSite attribute to work, it is a requirement to use a secure site (&lt;FONT face="courier new,courier"&gt;https://&lt;/FONT&gt;)&lt;BR /&gt;The only reason why there is the option to enable HasSecure and SameSite for HTTP in Qlik Sense is to facilitate the integration with a reverse proxy using SSL offloading.&lt;BR /&gt;In that use case, the connection between the end user and the reverse proxy will be HTTPS but the communication between the reverse proxy and Qlik Sense will be HTTP.&lt;BR /&gt;The connection will be seen as HTTPS in the end user's browser and the browser will allow the cookie to be set.&lt;BR /&gt;&lt;BR /&gt;Read more about SSL offloading:&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/TLS_termination_proxy" target="_blank" rel="noopener" data-cke-saved-href="https://en.wikipedia.org/wiki/TLS_termination_proxy"&gt;https://en.wikipedia.org/wiki/TLS_termination_proxy&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Information about how to set up SameSite in Qlik Sense:&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Missing-SameSite-attribute-now-blocks-requests-in/ta-p/1712551" target="_blank" rel="noopener" data-cke-saved-href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Missing-SameSite-attribute-now-blocks-requests-in/ta-p/1712551"&gt;Missing SameSite attribute blocks requests in Chrome 80 and later - Too many sessions in parallel&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 15:12:51 GMT</pubDate>
    <dc:creator>Sonja_Bauernfeind</dc:creator>
    <dc:date>2020-11-04T15:12:51Z</dc:date>
    <item>
      <title>Qlik Sense: SameSite doesn't work with insecure sites (HTTP)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-SameSite-doesn-t-work-with-insecure-sites-HTTP/ta-p/1758476</link>
      <description>&lt;P&gt;In Qlik Sense, when enabling the SameSite attribute and HasSecure attributes for a non-secure site (&lt;FONT face="courier new,courier"&gt;http://&lt;/FONT&gt;), the browser still refuses to set up the cookie.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Environments:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise for Windows November 2018 and later&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the SameSite attribute to work, it is a requirement to use a secure site (&lt;FONT face="courier new,courier"&gt;https://&lt;/FONT&gt;)&lt;BR /&gt;The only reason why there is the option to enable HasSecure and SameSite for HTTP in Qlik Sense is to facilitate the integration with a reverse proxy using SSL offloading.&lt;BR /&gt;In that use case, the connection between the end user and the reverse proxy will be HTTPS but the communication between the reverse proxy and Qlik Sense will be HTTP.&lt;BR /&gt;The connection will be seen as HTTPS in the end user's browser and the browser will allow the cookie to be set.&lt;BR /&gt;&lt;BR /&gt;Read more about SSL offloading:&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/TLS_termination_proxy" target="_blank" rel="noopener" data-cke-saved-href="https://en.wikipedia.org/wiki/TLS_termination_proxy"&gt;https://en.wikipedia.org/wiki/TLS_termination_proxy&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Information about how to set up SameSite in Qlik Sense:&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Missing-SameSite-attribute-now-blocks-requests-in/ta-p/1712551" target="_blank" rel="noopener" data-cke-saved-href="https://community.qlik.com/t5/Qlik-Support-Knowledge-Base/Qlik-Sense-Missing-SameSite-attribute-now-blocks-requests-in/ta-p/1712551"&gt;Missing SameSite attribute blocks requests in Chrome 80 and later - Too many sessions in parallel&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 15:12:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-SameSite-doesn-t-work-with-insecure-sites-HTTP/ta-p/1758476</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2020-11-04T15:12:51Z</dc:date>
    </item>
  </channel>
</rss>

