4.1.1.4 Ensure 'cookieSecure' secure attribute is set to 'true'

Information

The secure flag on a cookie will restrict the browser to send the cookies only on encrypted channels like HTTPS.

Cookies with the secure flag will only be sent over encrypted HTTPS requests.

Solution

Set the cookieSecure attribute to true in the httpSession element in the ${server.config.dir}/configDropins/overrides/<any file name>.xml

<httpSession cookieSecure="true"/>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: f01f4b2dd417fd65e9f85d03d8ccd409e8da858e3b9474765945e0622af25445