UCF STIG Viewer Logo

tc Server HORIZON must set the secure flag for cookies.


Finding ID Version Rule ID IA Controls Severity
V-240872 VRAU-TC-000900 SV-240872r879810_rule Medium
Cookies can be sent to a client using TLS/SSL to encrypt the cookies, but TLS/SSL is not used by every hosted application since the data being displayed does not require the encryption of the transmission. To safeguard against cookies, especially session cookies, being sent in plaintext, a cookie can be encrypted before transmission. To force a cookie to be encrypted before transmission, the cookie Secure property can be set. As a Tomcat derivative, tc Server is based in part on the Java Servlet specification. Servlet 3.0 (Java EE 6) introduced a standard way to configure secure attribute for the session cookie, this can be done by applying the correct configuration in web.xml.
VMware vRealize Automation 7.x tc Server Security Technical Implementation Guide 2023-10-03


Check Text ( C-44105r674358_chk )
At the command prompt, execute the following command:

grep -E '' /opt/vmware/horizon/workspace/conf/web.xml

If the value of the node is not set to "true" or is missing, this is a finding.
Fix Text (F-44064r674359_fix)
Navigate to and open /opt/vmware/horizon/workspace/conf/web.xml.

Navigate to the node.

Add the --> node setting to the node.

Note: The --> node should be configured per the following: