Check: 5.049
Windows XP STIG:
5.049
(in versions v6 r1.32 through v1 r0)
Title
Terminal Services is not configured to disconnect clients when time limits are exceeded. (Cat II impact)
Discussion
This setting, which is located under the Sessions section of the Terminal Services configuration option, controls whether or not clients are forcefully disconnected if their terminal services time limit is exceeded. If time limits are established for users, they should be enforced.
Check Content
If the following registry value doesn’t exist or its value is not set to 1, then this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows NT\Terminal Services\ Value Name: fResetBroken Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Sessions “Terminate Session When Time Limits are Reached” to “Enabled”.
Additional Identifiers
Rule ID: SV-3460r1_rule
Vulnerability ID: V-3460
Group Title: Terminal Services - Enforce Session Time Limit
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |