3.16 (L1) Host must configure a session timeout for the API

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A designated timeout ensures that sessions are not left open indefinitely, thereby reducing the exposure window for potential security threats. The parameter governing this behavior is Config.HostAgent.vmacore.soap.sessionTimeout with a recommended setting of 30 seconds.

A session timeout ensures that potential security threats from unauthorized users or malicious software exploiting open sessions are significantly reduced.

Solution

Impact:

There is no functional impact noted when configuring this security control, making it a low-risk enhancement towards securing the ESXi environment.

See Also

https://workbench.cisecurity.org/benchmarks/15784