Skip to content

The Automation Controller web server must manage sessions.

An XCCDF Rule

Description

Session management on client and server is required to protect identity and authorization information. Sessions for the Automation Controller web server, if compromised, could lead to execution of jobs on remote endpoints as if authenticated. Satisfies: SRG-APP-000001-WSR-000002, SRG-APP-000001-WSR-000001, SRG-APP-000295-WSR-000012, SRG-APP-000295-WSR-000134

ID
SV-256940r960735_rule
Version
APWS-AT-000020
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Log in to Automation Controller as an administrator and navigate to Settings >> System >> Miscellaneous Authentication.

Click "Edit".

Set the following parameters: