STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

The vCenter Server must terminate management sessions after 10 minutes of inactivity.

DISA Rule

SV-243126r719621_rule

Vulnerability Number

V-243126

Group Title

SRG-APP-000190

Rule Version

VCTR-67-000071

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the timeout value by editing the "webclient.properties" file.

On the vCenter Server locate the "webclient.properties" file in
C:\ProgramData\VMware\vCenterServer\cfg\vsphere-client

Edit the file to include the line "session.timeout = 10" where "10" is the timeout value in minutes. Uncomment the line if necessary.

After editing the file the vSphere Client service must be restarted.

Check Contents

Note: For vCenter Server Appliance, this is not applicable.

By default, vSphere Client sessions terminate after "120" minutes of idle time, requiring the user to log in again to resume using the client. You can view the timeout value by viewing the "webclient.properties" file.

On the vCenter Server locate the "webclient.properties" file in
C:\ProgramData\VMware\vCenterServer\cfg\vsphere-client

Find the "session.timeout =" line in the "webclient.properties" file.

If the session timeout is not set to "10" in the "webclient.properties" file, this is a finding.

Vulnerability Number

V-243126

Documentable

False

Rule Version

VCTR-67-000071

Severity Override Guidance

Note: For vCenter Server Appliance, this is not applicable.

By default, vSphere Client sessions terminate after "120" minutes of idle time, requiring the user to log in again to resume using the client. You can view the timeout value by viewing the "webclient.properties" file.

On the vCenter Server locate the "webclient.properties" file in
C:\ProgramData\VMware\vCenterServer\cfg\vsphere-client

Find the "session.timeout =" line in the "webclient.properties" file.

If the session timeout is not set to "10" in the "webclient.properties" file, this is a finding.

Check Content Reference

M

Target Key

5399

Comments