Ensure Session Timeout is 30 minutes or less

Information

Specifies how long a session can go unused before it is no longer valid.

Solution

1. Expand Servers
2. Click WebSphere application servers
3. Click the name of the server
4. Click Session management
5. Set Session timeout to 30 minutes or less
6. Click Apply
7. Click Save
8. Restart the WebSphere Application Server

See Also

https://www.ibm.com/developerworks/websphere/zones/was/security/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5

Plugin: Unix

Control ID: c4666a98978201e2c24f4dbd92faa22d3676e021a9431a6275bee0450bb3ef87