SV-54384r3_rule
V-41807
SRG-APP-000224-WSR-000136
SRG-APP-000224-WSR-000136
CAT II
10
Configure the web server to generate random and unique session identifiers that cannot be reliably reproduced.
Review the web server documentation and deployed configuration to verify that random and unique session identifiers are generated.
Access the web server ID generator function and generate two IDs using the same input.
If the web server is not configured to generate random and unique session identifiers, or the ID generator generates the same ID for the same input, this is a finding.
V-41807
False
SRG-APP-000224-WSR-000136
Review the web server documentation and deployed configuration to verify that random and unique session identifiers are generated.
Access the web server ID generator function and generate two IDs using the same input.
If the web server is not configured to generate random and unique session identifiers, or the ID generator generates the same ID for the same input, this is a finding.
M
2557