4.1.2.4 Ensure 'ssoRequiresSSL' secure attribute is set to 'true' for the LTPA Cookies

Information

Cookies with the secure flag will only be sent over encrypted HTTPS requests.

Transport cookies over a secure TLS connection to avoid clear text transmission of the cookie information. A stolen cookie by a third-party intruder can allow them to act as that user until it expires

Solution

Set the ssoRequiresSSL attribute is set to true in the webAppSecurity element on ${server.config.dir}/configDropins/overrides/*.xml

<webAppSecurity ssoRequiresSSL="true" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 35d8667af774398db9ba91a40243f11777a77d882181275e477ebbabcbd2036c