HPE OneView
cancel
Showing results for 
Search instead for 
Did you mean: 

Closing Browser doesn't Log Out of OneView

 
AustinKosinBAH
Occasional Visitor

Closing Browser doesn't Log Out of OneView

Hello,

We are looking for a setting or some configuration that clears the cookies upon exiting the browser.  Right now, if you don't log out and just close the browser, you can open the browser and your session will still be up.  This can pose a security problem for us.

 

Thanks,

Austin

2 REPLIES 2
Dennis Handly
Acclaimed Contributor

Re: Closing Browser doesn't Log Out of OneView

Do these cookies have an expiration time?

AustinKosinBAH
Occasional Visitor

Re: Closing Browser doesn't Log Out of OneView

According to HPE, 24 hours.

 

"In the browser, a cookie stores the session ID of the authenticated user. Although the cookie is deleted when you close the browser, the session is valid on the appliance until you log out. Logging out ensures that the session on the appliance is invalidated. NOTE: If you close the browser, any open sessions will be invalidated within 24 hours."