SV-220339r960735_rule
V-220339
SRG-APP-000001-DB-000031
ML09-00-000100
CAT III
10
Determine whether the system documentation specifies limits on the number of concurrent DBMS sessions per account by type of user. If it does not, assume a limit of 10 for database administrators and 2 for all other users.
Fix the concurrent-sessions settings in MarkLogic.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the App Server to be fixed resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select the App Server in which in which to fix session limits. The App Server Configuration page displays.
5. In the concurrent request limit field, enter a value corresponding to the organization-defined maximum number of concurrent user sessions to allow.
6. Repeat for all App Servers.
Determine whether the system documentation specifies limits on the number of concurrent DBMS sessions per account by type of user. If it does not, assume a limit of 10 for database administrators and 2 for all other users.
Check the concurrent-sessions settings in the MarkLogic.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select the App Server in which in which to check session limits. The App Server Configuration page displays.
5. Inspect the concurrent request limit field; a value of 0 means there is no concurrent request limit (unlimited), and this is a finding.
6. If a value other than 0 but not equal to the organization-defined number is set, this is a finding.
7. Repeat for all App Servers.
V-220339
False
ML09-00-000100
Determine whether the system documentation specifies limits on the number of concurrent DBMS sessions per account by type of user. If it does not, assume a limit of 10 for database administrators and 2 for all other users.
Check the concurrent-sessions settings in the MarkLogic.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select the App Server in which in which to check session limits. The App Server Configuration page displays.
5. Inspect the concurrent request limit field; a value of 0 means there is no concurrent request limit (unlimited), and this is a finding.
6. If a value other than 0 but not equal to the organization-defined number is set, this is a finding.
7. Repeat for all App Servers.
M
4064