EDR: Browser sessions persist after service restart
book
Article ID: 292364
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Users are still able to browse webpages without re-authentication after a restart of EDR services
Cause
An update in one of the services has caused persistence across sessions
Resolution
Workaround
- Stop cb-enterprise
- Delete file /var/cb/redis/dump.rdb
- Update /etc/cb/redis.conf and /etc/cb/redis.conf.template by removing the '#' at the start of the line for
- Start cb-enterprise
Additional Information
To test fix, connect to the UI and then restart services. The session should be closed and require the user to sign in
/usr/share/cb/cbservice cb-enterprise restart
Feedback
thumb_up
Yes
thumb_down
No