10.10 Configure connectionTimeout

Information

The connectionTimeout setting allows Tomcat to close idle sockets after a specific amount of time to save system resources. Closing idle sockets reduces system resource usage thus can provide better performance and help protect against Denial of Service attacks.

Solution

Within $CATALINA_HOME/conf/server.xml ensure each connector is configured to the connectionTimeout setting that is optimal based on hardware resources, load, and number of concurrent connections.

See Also

https://workbench.cisecurity.org/files/267

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12

Plugin: Unix

Control ID: 8017bab26cd6868bf92ebb30dbaa92f4a3b7c4bb3c528d3867dfb71f21ff417a