4.4.3 Ensure 'logoutPageRedirectDomainNames' is set to relevant domain names for logout page redirects

Information

For logout page redirects, explicit domain names can be listed.

Defining approved domain names for redirects prevents the server from redirecting to a disallowed domain.

Solution

Set the logoutPageRedirectDomainNames attribute in the webAppSecurity element to a pipe(|) separated list of domain names that are allowed for the logout page redirect in ${server.config.dir}/configDropins/overrides/*.xml For Example, for the two domains ibm.com and openliberty.io

<webAppSecurity logoutPageRedirectDomainNames="ibm.com|openliberty.io" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Unix

Control ID: bf6dbd853a079f874cc533d72b0daa069ba8ae963be4529d4f9023fab9bac5e0