SV-102621r1_rule
V-92533
SRG-APP-000220-WSR-000201
AS24-W2-000460
CAT II
10
Open the <'INSTALL PATH'>\conf\httpd.conf file.
Set the "SessionMaxAge" directive to a value of "600" or less; add the directive if it does not exist.
Restart the Apache service.
Review the <'INSTALL PATH'>\conf\httpd.conf file.
Search for the following directive:
SessionMaxAge
Verify the value of "SessionMaxAge" is set to "600" or less.
If the "SessionMaxAge" does not exist or is set to more than "600", this is a finding.
V-92533
False
AS24-W2-000460
Review the <'INSTALL PATH'>\conf\httpd.conf file.
Search for the following directive:
SessionMaxAge
Verify the value of "SessionMaxAge" is set to "600" or less.
If the "SessionMaxAge" does not exist or is set to more than "600", this is a finding.
M
3419