STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Red Hat Ansible Automation Controller Application Server Security Technical Implementation Guide

V-256896

CAT II (Medium)

Automation Controller must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.

Rule ID

SV-256896r904435_rule

STIG

Red Hat Ansible Automation Controller Application Server Security Technical Implementation Guide

Version

V1R2

CCIs

CCI-000054

Discussion

Application management includes the ability to control the number of sessions that utilize an application by all accounts and/or account types. Limiting the number of allowed sessions is helpful in limiting risks related to denial-of-service attacks.<br /><br />Automation Controllers host and expose business logic and application processes.<br /><br />Automation Controller limits the maximum number of concurrent sessions in a manner that affects the entire application server or on an individual application basis.<br /><br />The settings must follow DOD-recommended values, but the settings should be configurable to allow for future DOD direction.<br /><br />While the DOD will specify recommended values, the values can be adjusted to accommodate the operational requirement of a given system.<br /><br />Satisfies: SRG-APP-000001-AS-000001, SRG-APP-000295-AS-000263

Check Content

As a System Administrator for each Automation Controller host, navigate to the Automation Controller web administrator console:<br />Settings >> System >> Miscellaneous Authentication settings.<br /><br />Verify the "Maximum Number of simultaneous logged in sessions" field is set according to policy.<br /><br />If this configuration setting does not match the organizationally defined maximum, or is set to -1 (negative one), this is a finding.

Fix Text

As a System Administrator for each Automation Controller host, navigate to the Automation Controller web administrator console:<br />Settings >> System >> Miscellaneous Authentication settings.<br /><br />Click "Edit".<br /><br />Change "Maximum Number of simultaneous logged in sessions" to match the organizationally defined maximum or greater than 0.<br /><br />Click "Save".