<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security considerations for dashboards access over internet in QlikView</title>
    <link>https://community.qlik.com/t5/QlikView/Security-considerations-for-dashboards-access-over-internet/m-p/382960#M1274630</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently using the following set-up on our QV environment to provide access to end users over internet. These are the internal users who would be accessing the dashboards using iPad or other internet devises.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. We have a SSO solution which handles the secuirty and passes the login credentials as a HTTP header.&lt;/P&gt;&lt;P&gt;2. QlikView web server (no IIS) uses header authentication to read the header values and pass the same to QVS&lt;/P&gt;&lt;P&gt;3. QVS uses the DMS authorization to publish dashboards to users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This configuration is working fine for me. But I have the following queries with respect to the security levels of this solution. Can you pelase help me to understand how QlikView handles the below when the above set of configurations are used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP Trace:&lt;/P&gt;&lt;P&gt;Are there any options available to disable trace for QWS?&lt;/P&gt;&lt;P&gt;Session Fixation:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;The application sets a session identifier (cookie) for every new visitor prior to authentication. On successful login the session identifier &lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;is not refreshed. can this cause session fixation?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Secure flag on Session ID:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;How to set the secure flag for the session id? Having this only let browser to send the cookie over HTTPS. Is there a way to change this setting?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;HTTPonly flag on Session ID:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Having this flag allows access to the cookie through client side script. Is there a way to configure this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Murali&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Jan 2026 18:19:17 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2026-01-26T18:19:17Z</dc:date>
    <item>
      <title>Security considerations for dashboards access over internet</title>
      <link>https://community.qlik.com/t5/QlikView/Security-considerations-for-dashboards-access-over-internet/m-p/382960#M1274630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently using the following set-up on our QV environment to provide access to end users over internet. These are the internal users who would be accessing the dashboards using iPad or other internet devises.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. We have a SSO solution which handles the secuirty and passes the login credentials as a HTTP header.&lt;/P&gt;&lt;P&gt;2. QlikView web server (no IIS) uses header authentication to read the header values and pass the same to QVS&lt;/P&gt;&lt;P&gt;3. QVS uses the DMS authorization to publish dashboards to users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This configuration is working fine for me. But I have the following queries with respect to the security levels of this solution. Can you pelase help me to understand how QlikView handles the below when the above set of configurations are used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP Trace:&lt;/P&gt;&lt;P&gt;Are there any options available to disable trace for QWS?&lt;/P&gt;&lt;P&gt;Session Fixation:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;The application sets a session identifier (cookie) for every new visitor prior to authentication. On successful login the session identifier &lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;is not refreshed. can this cause session fixation?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Secure flag on Session ID:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;How to set the secure flag for the session id? Having this only let browser to send the cookie over HTTPS. Is there a way to change this setting?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;HTTPonly flag on Session ID:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Having this flag allows access to the cookie through client side script. Is there a way to configure this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Murali&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2026 18:19:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-considerations-for-dashboards-access-over-internet/m-p/382960#M1274630</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2026-01-26T18:19:17Z</dc:date>
    </item>
  </channel>
</rss>

