In the context of:
Irrespective of whether ESCWA has verification required (and is therefore restricted), all clients will require a session to perform actions.
ESCWA has a session timeout which can be removed.
Timeouts limit exposure to a variety of session-based attacks and therefore should be implemented.
Irrespective of whether a Directory Server has verification required (and is therefore restricted), all clients will require a session to perform actions.
Directory Servers have a session timeout which can be removed.
Timeouts limit exposure to a variety of session-based attacks and therefore should be implemented.
To ensure ESCWA has a session timeout enabled, use ESCWA to perform the following steps:
This opens the Enterprise Server Administration Configuration dialog box.
To ensure a Directory Server has a session timeout enabled, use ESCWA to perform the following steps:
This takes you to the Directory Server Configuration page.
This ensures that the API session timeout is set to the specified value.