VCENTER-000027 - The system must set a timeout for all thick-client logins without activity

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

An inactivity timeout must be set for the vSphere Client (Thick Client). This client-side setting can be changed by users, so this must be set by default and re-audited. Automatic session termination minimizes risk and reduces the potential for unauthorized access to vCenter.

Solution

On each Windows computer with the vSphere Client installed: Set a 15 minute (maximum) timeout in the VpxClient.exe.config file: Locate the VpxClient.exe.config file using the Windows OS search facility. Next, right click on VpxClient.exe.config and edit the file using an editor, such as Notepad. In the <cmdlineFallback>... </cmdlineFallback> section, modify the <inactivityTimeout>X</inactivityTimeout> where X is the (maximum=15) number of minutes before the vSphere Client will automatically disconnect from the server. Exit, saving the file. Set a 15 minute (maximum) timeout execution flag when starting the vSphere Client executable: Locate the vSphere Client executable icon on the desktop, right click, and select properties. Add '-inactivityTimeout X', where X is the (maximum=15) number of minutes before the vSphere Client will automatically disconnect from the server

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-39563, Rule-ID|SV-51421r1_rule, STIG-ID|VCENTER-000027, Vuln-ID|V-39563

Plugin: VMware

Control ID: b10f0f207720a6c99f70d375515107f1ee35f6391525d75913ec68503d8e7f6d