SV-214435r508658_rule
V-214435
SRG-APP-000439-WSR-000152
IISW-SV-000152
CAT II
10
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Under "Management" section, double-click the "Configuration Editor" icon.
From the "Section:" drop-down list, select 'system.webServer/asp".
Expand the "session" section.
Select "True" for the "keepSessionIdSecure" setting.
Select "Apply" from the "Actions" pane.
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Under "Management" section, double-click the "Configuration Editor" icon.
From the "Section:" drop-down list, select “system.webServer/asp".
Expand the "session" section.
Verify the "keepSessionIdSecure" is set to "True".
If the "keepSessionIdSecure" is not set to "True", this is a finding.
V-214435
False
IISW-SV-000152
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Under "Management" section, double-click the "Configuration Editor" icon.
From the "Section:" drop-down list, select “system.webServer/asp".
Expand the "session" section.
Verify the "keepSessionIdSecure" is set to "True".
If the "keepSessionIdSecure" is not set to "True", this is a finding.
M
4000