VCST-67-000019 - The Security Token Service must limit the number of allowed connections.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Limiting the number of established connections to the Security Token Service is a basic denial of service protection. Servers where the limit is too high or unlimited can potentially run out of system resources and negatively affect system availability.

Solution

Navigate to and open /usr/lib/vmware-sso/vmware-sts/conf/server.xml.

Navigate to the <Connector> configured with port='${bio-custom.http.port}'.

Add or change the following value:

acceptCount='100'

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001094, Rule-ID|SV-239670r679082_rule, STIG-ID|VCST-67-000019, Vuln-ID|V-239670

Plugin: Unix

Control ID: 91f440f33e2845adf4c50e079847f222dfb69c8162700ffadff676861a6aab1f