#file://etc/hosts www.facebook.com facebook.com static.ak.fbcdn.net www.static.ak.fbcdn.net login.facebook.com www.login.facebook.com fbcdn.net www.fbcdn.net fbcdn.com www.fbcdn.com static.ak.connect.facebook.com www.static.ak.connect.facebook.com


i am confused about apache respect of RFC it's written that header should not excess 4k but as specified in cookie RFC… min req are : 20 cookies of 4k each

knowing that cookies are passed in the http header the size of the Cookie: header field should not excess 4k and if i am right there should be 20 x 4k limit not only 4k

@ http://www.faqs.org/rfcs/rfc2109.html

  • at least 4096 bytes per cookie (as measured by the size of the

characters that comprise the cookie non-terminal in the syntax

      description of the Set-Cookie header)
  • at least 20 cookies per unique host or domain name




LimitRequestFieldSize Directive

@ http://tomcat.apache.org/tomcat-5.0-doc/config/http.html


The maximum size of the request and response HTTP header, specified in bytes. If not specified, this attribute is set to 4096 (4 KB).

Apache reports :

Bad Request
Your browser sent a request that this server could not understand.
Size of a request header field exceeds server limit.
Number and size limits of a cookie in Internet Explore http://support.microsoft.com/?id=306070

How to limit the header size of the HTTP transmission that IIS accepts from a client in Windows 2000 http://support.microsoft.com/kb/310156

Netscape Cookies doc


