4.1.2.2 Ensure 'ssoDomainNames' attribute is configured for the authentication cookies.

Information

The domain name attribute in a cookie specifies which hosts can receive the cookie.

Cookies that have their domain attribute set to a specific domain will only be sent to the hosts in that domain or sub-domain which helps in controlling its propagation.

Solution

Add the appropriate domain name to the ssoDomainNames attribute in the webAppSecurity element in ${server.config.dir}/configDropins/overrides/<any file name>.xml

For example, to add mySubDomain.myCompany.com

<webAppSecurity ssoDomainNames="mySubDomain.myCompany.com"/>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23

Plugin: Unix

Control ID: 6f82e94bfe8ef230a3b7afbc621740faf801230fa95adfbe96ac6990f5265520