UCF STIG Viewer Logo

When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, the F5 BIG-IP appliance must be configured to enable the HTTP Only flag.


Overview

Finding ID Version Rule ID IA Controls Severity
V-260058 F5BI-AP-000241 SV-260058r947399_rule Low
Description
To guard against cookie hijacking, only the BIG-IP APM controller and client must be able to view the full session ID. Setting the APM HTTP Only flag ensures that a third party will not have access to the active session cookies. This option is only applicable to the LTM+APM access profile type. Other access profile types require access to various session cookies to fully function. Sites must conduct operational testing prior to enabling this setting. For implementations with connectivity resources (such as Network Access, Portal Access, etc.), do not set BIG-IP APM cookies with the HTTP Only flag.
STIG Date
F5 BIG-IP Access Policy Manager Security Technical Implementation Guide 2024-01-26

Details

Check Text ( C-63789r947397_chk )
If the Access Profile Type is not LTM+APM and it uses connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, this is not a finding.

From the BIG-IP GUI:
1. Access >> Profiles/Policies >> Access profile name >> SSO/Auth Domains.
2. Under "Cookie Options", verify "HTTP Only" is enabled.

If the F5 BIG-IP appliance does not enable the HTTP Only flag, this is a finding.
Fix Text (F-63695r947398_fix)
When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, set the HTTP Only flag.

From the BIG-IP GUI:
1. Access >> Profiles/Policies >> Access profile name >> SSO/Auth Domains.
2. Under "Cookie Options", check the box next to "HTTP Only".