UCF STIG Viewer Logo

The Horizon Connection Server must reauthenticate users after a network interruption.


Overview

Finding ID Version Rule ID IA Controls Severity
V-246898 HRZV-7X-000017 SV-246898r768654_rule Medium
Description
Given the remote access nature of Horizon Connection Server, the client must be ensured to be under positive control as much as is possible from the server side. As such, whenever a network interruption causes a client disconnect, that session must be reauthenticated upon reconnection. To allow a session resumption would be convenient but would allow for the possibility of the endpoint being taken out of the control of the intended user and reconnected to a different network, in control of a bad actor who could then resume the disconnected session.
STIG Date
VMware Horizon 7.13 Connection Server Security Technical Implementation Guide 2021-07-30

Details

Check Text ( C-50330r768652_chk )
Log in to the Horizon 7 Console. From the left pane, navigate to Settings >> Global Settings. In the right pane, click the "Security Settings" tab. Locate the "Reauthenticate Secure Tunnel Connections After Network Interruption" setting.

If the "Reauthenticate Secure Tunnel Connections After Network Interruption" setting is set to "No", this is a finding.
Fix Text (F-50284r768653_fix)
Log in to the Horizon 7 Console. From the left pane, navigate to Settings >> Global Settings. In the right pane, click the "Security Settings" tab. Click "Edit". Check the box next to "Reauthenticate secure tunnel connections after network interruption". Click "OK".