10.9 Configure connectionTimeout

Information

The connectionTimeout setting allows Tomcat to close idle sockets after a specific amount of time to save system resources.

Closing idle sockets reduces system resource usage which can provide better performance and help protect against Denial of Service attacks.

Solution

Set the connectionTimeout for each connector in $CATALINA_HOME/conf/server.xml ensure to the optimal number of milliseconds based on hardware resources, load, and number of concurrent connections.

connectionTimeout="60000"

Impact:

This timeout will also apply when reading any request body when disableUploadTimeout is not set to false

See Also

https://workbench.cisecurity.org/benchmarks/15137

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|5.1

Plugin: Unix

Control ID: 034fa14d35752af899525a7ffea89eb11af0f5f9d6cab818e5089dd2800b0946