<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security</title><link>http://forums.asp.net/25.aspx</link><description>All about ASP.NET security (authentication, authorization, membership, roles, etc.) and the Login controls. &lt;a href="http://aspadvice.com/SignUp/list.aspx?l=24&amp;c=17" target="_blank"&gt;Email List&lt;/a&gt;</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1697111.aspx</link><pubDate>Sun, 06 May 2007 16:48:20 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1697111</guid><dc:creator>mike beal</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1697111.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1697111</wfw:commentRss><description>&lt;p&gt;I just caught this issue myself wth a site I'm rolling out next week. I was wondering if 'persistent cookies' has more to do with the&amp;nbsp;IE browser settings (particularly IE 7)&amp;nbsp;the users are using rather than anthing wrong we are doing with out cookies or logon controls. I'm looking through those crytic settings now in my browser. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Has anyone persued this line of thought?&amp;nbsp;&amp;nbsp; I am using the login control and although it appears I've set it correctly to persist the cookie it doesn't last any longer than the session length. &lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1657566.aspx</link><pubDate>Mon, 09 Apr 2007 15:51:16 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1657566</guid><dc:creator>sanchita_ind</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1657566.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1657566</wfw:commentRss><description>&lt;blockquote&gt;&lt;div&gt;&lt;img src="http://forums.asp.net/Themes/default/images/icon-quote.gif" /&gt; &lt;strong&gt;Cody21:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;p&gt;Has ANYONE actually got this to work?&amp;nbsp; I think there's some other issue going on that I can't quite put my finger on. I modifed my web.confgi file and in the FORMS section, added the TIMEOUT=500000 value.&amp;nbsp; It;s almost like the Sesson State is overriding the FORMS AUTH value. That is, after around 20 mins, I get TIMED OUT and am forced to re-LOGIN. ....&amp;nbsp; I check and my COOKIE for FORMS AUTH is still there. It's behaving like it's not even checking the cookie that i set.&lt;/p&gt;
&lt;p&gt;Some more background - in case it makes a difference. I do NOT require login authentication for the root of my site (&lt;a href="http://www.cityswingsf.com/"&gt;www.cityswingsf.com&lt;/a&gt;) ...&amp;nbsp; I only force the authentication when you hit a sub-folder of my site that is for Members only. So I have a separate web.config file that uses Roles Mgt for those secured pages ... But like I said, after they login - even with the REMEMBER ME selected - after some time, or even after a browser recycle, it seems to ignore the cookie...&lt;/p&gt;
&lt;p&gt;Anyone else???&amp;nbsp; (Oh, and I currently have cookies DISABLED due to this problem until I can get something that works!)&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Well in my case Forms authentication timeout value is picked up and not Session State's timeout. But the problem being that both persistent and non persistent would pick up the same timeout value. Microsoft has put the persistent cookie's lifetime as configurable but how come both would pick up the same timeout. So we will be forcing a user to remain logged in even if he doesn't check the "Remember Me" checkbox...&lt;/p&gt;&lt;p&gt;I am aware of the "Session Variables lost" problem. Thanks for that input.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Regards,&lt;/p&gt;&lt;p&gt;Sanchita&lt;br /&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1640543.aspx</link><pubDate>Wed, 28 Mar 2007 08:32:10 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1640543</guid><dc:creator>XiaoYong Dai – MSFT</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1640543.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1640543</wfw:commentRss><description>&lt;p&gt;&lt;font face="Times New Roman" size=3&gt;Hi &amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Times New Roman" size=3&gt;I guess&amp;nbsp;that it's because resource recycling, &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;See our KB article and you'll know in general &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316148"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316148&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Times New Roman" size=3&gt;Hope it helps&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Times New Roman" size=3&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1637967.aspx</link><pubDate>Mon, 26 Mar 2007 21:43:42 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1637967</guid><dc:creator>Cody21</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1637967.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1637967</wfw:commentRss><description>&lt;p&gt;Has ANYONE actually got this to work?&amp;nbsp; I think there's some other issue going on that I can't quite put my finger on. I modifed my web.confgi file and in the FORMS section, added the TIMEOUT=500000 value.&amp;nbsp; It;s almost like the Sesson State is overriding the FORMS AUTH value. That is, after around 20 mins, I get TIMED OUT and am forced to re-LOGIN. ....&amp;nbsp; I check and my COOKIE for FORMS AUTH is still there. It's behaving like it's not even checking the cookie that i set.&lt;/p&gt;
&lt;p&gt;Some more background - in case it makes a difference. I do NOT require login authentication for the root of my site (&lt;a href="http://www.cityswingsf.com/"&gt;www.cityswingsf.com&lt;/a&gt;) ...&amp;nbsp; I only force the authentication when you hit a sub-folder of my site that is for Members only. So I have a separate web.config file that uses Roles Mgt for those secured pages ... But like I said, after they login - even with the REMEMBER ME selected - after some time, or even after a browser recycle, it seems to ignore the cookie...&lt;/p&gt;
&lt;p&gt;Anyone else???&amp;nbsp; (Oh, and I currently have cookies DISABLED due to this problem until I can get something that works!)&lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1637907.aspx</link><pubDate>Mon, 26 Mar 2007 20:53:16 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1637907</guid><dc:creator>sanchita_ind</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1637907.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1637907</wfw:commentRss><description>&lt;p&gt;coupla links which discuss this issue -&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;http://www.dotnetnuke.com/Community/BlogsDotNetNuke/tabid/825/rssid/28/Default.aspx&lt;br /&gt;&lt;/p&gt;&lt;p&gt;http://pluralsight.com/blogs/keith/archive/2006/05/24/25023.aspx?Pending=true&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;looks like the persistent cookie's lifetime depends on the form's timeout value in web.config... so we will have to increase that till days n weeks.. &lt;img src="http://forums.asp.net/emoticons/emotion-40.gif" alt="Hmm" /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;sanchita&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1635671.aspx</link><pubDate>Sun, 25 Mar 2007 04:18:12 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1635671</guid><dc:creator>sanchita_ind</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1635671.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1635671</wfw:commentRss><description>&lt;p&gt;ok so my understanding to this problem now is that i can try modifying the web.config n set the timeout to weeks etc.. &lt;/p&gt;&lt;p&gt;n yes u r rite this is not tht a big a thing,&amp;nbsp; wch we shud b wasting our time on..&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;neways if you hear of anything keep posting..&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1635287.aspx</link><pubDate>Sat, 24 Mar 2007 16:35:24 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1635287</guid><dc:creator>Cody21</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1635287.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1635287</wfw:commentRss><description>&lt;blockquote&gt;&lt;div&gt;&lt;img src="http://forums.asp.net/Themes/default/images/icon-quote.gif" /&gt; &lt;strong&gt;sanchita_ind:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt; 
&lt;div&gt;Hello everyone,&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;I am having a problem with persistent cookies. Even after setting "CreatePersistentCookie" to true in "&lt;font size=2&gt;FormsAuthentication.SetAuthCookie" I'm somehow being logged out after the specifed timeout provided&amp;nbsp;in "forms" element of web.config. &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=2&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font size=2&gt;I read somewhere that persistent cookies take their timeout from the timeout attribute on the forms authentcation node. If I have to enter a timeout of days/weeks then it doesnt really make sense to make my cookie persist in this fashion, that defies the purpose of persistent cookies. &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Any insights are welcome &lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Thanks&lt;/div&gt;
&lt;div&gt;Sanchita&lt;/div&gt;
&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/blockquote&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;yea, i have been dealing with the exact same issue for like 3 weeks now since developing my new site. I am using the LOGIN control in EWD (or VS2005 for that matter). Quite honestly, i don't understand why this is so difficult to implement. I really believe that Microsoft needs to document the specific steps &amp;amp; requirements to allow a LOGIN to remain LOGGED IN for some controlled (by web.config) length of time regardless whether a user shuts down their browser or not. I am using MySql as well. I have seen all kinds of different suggestions on how to fix this -- from writing our own code to managing our own cookies, etc..&amp;nbsp; If anyone knows how to successfully set web.config items - whether using Roles/Membership providers -- or WHATEVER - I think many many of us would benefit. Based on this FORUM, there are many of us struggling with this LOGIN control for ASP.NET 2.0&lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1635235.aspx</link><pubDate>Sat, 24 Mar 2007 14:52:03 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1635235</guid><dc:creator>sanchita_ind</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1635235.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1635235</wfw:commentRss><description>&lt;p&gt;hey thanks 4 the reply..&lt;/p&gt;&lt;p&gt;well that post was informative but didnt help that much on my issue cos i dont think we use RoleManager in our config..&lt;/p&gt;&lt;p&gt;the problem is with asp.net 2.0 i feel as i feel the Form's timeout value in web.config is the one who's responsible for persisting cookies.. If you know anything else please share..&lt;br /&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1635141.aspx</link><pubDate>Sat, 24 Mar 2007 11:07:01 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1635141</guid><dc:creator>upgView</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1635141.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1635141</wfw:commentRss><description>&lt;p&gt;Take a look here &lt;a href="http://forums.asp.net/thread/1555817.aspx"&gt;http://forums.asp.net/thread/1555817.aspx&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Hope that helps.&amp;nbsp;&lt;/p&gt;</description></item><item><title>Problem with Persistent Cookies</title><link>http://forums.asp.net/thread/1634863.aspx</link><pubDate>Fri, 23 Mar 2007 22:02:04 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:1634863</guid><dc:creator>sanchita_ind</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/1634863.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=1634863</wfw:commentRss><description>&lt;div&gt;Hello everyone,&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;I am having a problem with persistent cookies. Even after setting "CreatePersistentCookie" to true in "&lt;font size=2&gt;FormsAuthentication.SetAuthCookie" I'm somehow being logged out after the specifed timeout provided&amp;nbsp;in "forms" element of web.config. &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=2&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;font size=2&gt;I read somewhere that persistent cookies take their timeout from the timeout attribute on the forms authentcation node. If I have to enter a timeout of days/weeks then it doesnt really make sense to make my cookie persist in this fashion, that defies the purpose of persistent cookies. &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Any insights are welcome &lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Thanks&lt;/div&gt;
&lt;div&gt;Sanchita&lt;/div&gt;</description></item></channel></rss>