STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 vCenter Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2024:

The vCenter Server must terminate vSphere Client sessions after 10 minutes of inactivity.

DISA Rule

SV-256334r885613_rule

Vulnerability Number

V-256334

Group Title

SRG-APP-000190

Rule Version

VCSA-70-000089

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Administration >> Deployment >> Client Configuration.

Click "Edit" and enter "10" minutes into the "Session timeout" setting. Click "Save".

Note: If vCenter is not 7.0 U2 or newer, this setting is not available through the UI and must be checked with the "session.timeout" setting in the "/etc/vmware/vsphere-ui/webclient.properties file".

Check Contents

From the vSphere Client, go to Administration >> Deployment >> Client Configuration.

View the value of the "Session timeout" setting.

If "Session timeout" is not set to "10 minute(s)" or below, this is a finding.

Note: If vCenter is not 7.0 U2 or newer, this setting is not available through the UI and must be checked with the "session.timeout" setting in the "/etc/vmware/vsphere-ui/webclient.properties file".

Vulnerability Number

V-256334

Documentable

False

Rule Version

VCSA-70-000089

Severity Override Guidance

From the vSphere Client, go to Administration >> Deployment >> Client Configuration.

View the value of the "Session timeout" setting.

If "Session timeout" is not set to "10 minute(s)" or below, this is a finding.

Note: If vCenter is not 7.0 U2 or newer, this setting is not available through the UI and must be checked with the "session.timeout" setting in the "/etc/vmware/vsphere-ui/webclient.properties file".

Check Content Reference

M

Target Key

5517