1.12.13 Increase the entropy in session identifiers

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Having a server that has deterministic session identifiers can lead to session hijacking. Specifying a randomClass attribute allows for truly random session identifiers.

See Also

https://workbench.cisecurity.org/files/261

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23(3)

Plugin: Unix

Control ID: f1541cc0298557b977b364122fe9858ee29f546e10fcc66f2449188dd0ce021f