Skip to content

The Apache web server must generate a session ID using as much of the character set as possible to reduce the risk of brute force.

An XCCDF Rule