The Automation Controller web server must manage sessions.
An XCCDF Rule
Description
Session management on client and server is required to protect identity and authorization information. Sessions for the Automation Controller web server, if compromised, could lead to execution of jobs on remote endpoints as if authenticated. Satisfies: SRG-APP-000001-WSR-000002, SRG-APP-000001-WSR-000001, SRG-APP-000295-WSR-000012, SRG-APP-000295-WSR-000134
- ID
- SV-256940r960735_rule
- Version
- APWS-AT-000020
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Log in to Automation Controller as an administrator and navigate to Settings >> System >> Miscellaneous Authentication.
Click "Edit".
Set the following parameters: