4.4.5 Ensure 'logoutOnHttpSessionExpire' is set to 'true'

Information

Logout users after the HTTP session timer expires.

Logging out users after the HTTP session expires syncs the session and the LTPA authentication token and prompts the user to login again when accessing the resource.

Solution

Set the logoutOnHttpSessionExpire attribute to true in the webAppSecurity element on ${server.config.dir}/configDropins/overrides/*.xml

<webAppSecurity logoutOnHttpSessionExpire="true" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12

Plugin: Unix

Control ID: 7f93952ee72e8693754f3164025e04ec545054dd1e61fc3077d8caafee8c7d4e