1. Home
  2. Security Hardening
  3. DISA IIS 10.0 Site V2R1
  4. IIST-SI-000244 – IIS 10.0 website session IDs must be sent to the client using TLS.

IIST-SI-000244 – IIS 10.0 website session IDs must be sent to the client using TLS.

Details

The HTTP protocol is a stateless protocol. To maintain a session, a session identifier is used. The session identifier is a piece of data used to identify a session and a user. If the session identifier is compromised by an attacker, the session can be hijacked. By encrypting the session identifier, the identifier becomes more difficult for an attacker to hijack, decrypt, and use before the session has expired.

Solution

Follow the procedures below for each site hosted on the IIS 10.0 web server:

Access the IIS 10.0 Manager.

Select the website being reviewed.

Under ‘Management’ section, double-click the ‘Configuration Editor’ icon.

From the ‘Section:’ drop-down list, select ‘system.webServer/asp’.

Expand the ‘session’ section.

Select ‘True’ for the ‘keepSessionIdSecure’ setting.

Select ‘Apply’ from the ‘Actions’ pane.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles