4.1.2.7 Ensure 'trackLoggedOutSSOCookies' is set to 'true'

Information

The trackLoggedOutSSOCookies attribute keeps track of the LTPA cookies that are logged out in a running server.

Prevent the misuse of LTPA tokens after users have logged out.

Solution

Set trackLoggedOutSSOCookies to true in the webAppSecurity element in the ${server.config.dir}/configDropins/overrides/<any file name>.xml

<webAppSecurity trackLoggedOutSSOCookies="true" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23

Plugin: Unix

Control ID: 54cb545a46cb885c7c2a00fbe7805b0cb59f1eded66063a06c65b8745fc227de