STIGQter STIGQter: STIG Summary: VMW vSphere 6.5 vCenter Server for Windows Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The vCenter Server for Windows must terminate management sessions after 10 minutes of inactivity.

DISA Rule

SV-216828r612237_rule

Vulnerability Number

V-216828

Group Title

SRG-APP-000190

Rule Version

VCWN-65-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the timeout value by editing the "webclient.properties" file.

On the system where vCenter is installed locate the "webclient.properties" file.

Appliance:
/etc/vmware/vsphere-client/

Windows:
C:\ProgramData\VMware\vCenterServer\cfg\vsphere-client

Edit the file to include the line "session.timeout = 10" where "10" is the timeout value in minutes. Uncomment the line if necessary.

After editing the file the vSphere Web Client service must be restarted.

Check Contents

By default, vSphere Web Client sessions terminate after "120" minutes of idle time, requiring the user to log in again to resume using the client. You can view the timeout value by viewing the "webclient.properties" file.

On the system where vCenter is installed locate the "webclient.properties" file.

Appliance:
/etc/vmware/vsphere-client/

Windows:
C:\ProgramData\VMware\vCenterServer\cfg\vsphere-client

Find the "session.timeout =" line in the "webclient.properties" file.

If the session timeout is not set to "10" in the "webclient.properties" file, this is a finding.

Vulnerability Number

V-216828

Documentable

False

Rule Version

VCWN-65-000004

Severity Override Guidance

By default, vSphere Web Client sessions terminate after "120" minutes of idle time, requiring the user to log in again to resume using the client. You can view the timeout value by viewing the "webclient.properties" file.

On the system where vCenter is installed locate the "webclient.properties" file.

Appliance:
/etc/vmware/vsphere-client/

Windows:
C:\ProgramData\VMware\vCenterServer\cfg\vsphere-client

Find the "session.timeout =" line in the "webclient.properties" file.

If the session timeout is not set to "10" in the "webclient.properties" file, this is a finding.

Check Content Reference

M

Target Key

4030

Comments