STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

The vCenter Server must terminate management sessions after 10 minutes of inactivity.

DISA Rule

SV-243075r719468_rule

Vulnerability Number

V-243075

Group Title

SRG-APP-000190

Rule Version

VCTR-67-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to and open /etc/vmware/vsphere-client/webclient.properties. Remove any existing "session.timeout" line and add the following:

session.timeout = 10

Check Contents

Note: For vCenter Server Windows, this is not applicable.

On the vCenter Server, execute the following command:

# grep "^session\.timeout" /etc/vmware/vsphere-client/webclient.properties

Expected result:

session.timeout = 10

If the output does not match the expected result, this is a finding.

Vulnerability Number

V-243075

Documentable

False

Rule Version

VCTR-67-000004

Severity Override Guidance

Note: For vCenter Server Windows, this is not applicable.

On the vCenter Server, execute the following command:

# grep "^session\.timeout" /etc/vmware/vsphere-client/webclient.properties

Expected result:

session.timeout = 10

If the output does not match the expected result, this is a finding.

Check Content Reference

M

Target Key

5399

Comments