For the second time this month, the management GUI on a shared jump host was found logged in to the appliance since morning, unattended. The customer asks what the platform itself can do about the habit. What is the right answer?
Select an answer to reveal the explanation.
Short Explanation
An abandoned console is a dare. Set the session idle timeout to whatever your security posture can live with, and let the platform close what people won't - while logging out stays the rule. And no, a locked monitor on the jump host protects nothing; the appliance session behind it is still sitting there wide open.
Full Explanation
The platform-side answer to an open management session is session timeout: DD OS management sessions - GUI and command line alike - can be configured to disconnect after a defined idle period, so an unattended console closes on its own without relying on the human who walked away. The configuration is a balance: tight enough to bound an unattended browser, loose enough not to fight how people actually watch backups overnight, and it complements rather than replaces the logout rule. Restricting GUI reachability to approved subnets is a real and worthwhile control for who can reach the console in the first place, but it is orthogonal to the stale-session problem - a session already open on the sanctioned jump host stays open no matter who else is excluded. Retiring the GUI does not retire the problem either: SSH sessions persist after an operator walks off until something times them out, so the same idle-timeout reasoning applies regardless, and the loss of a management interface is a real cost for no protective gain. A workstation screen lock hides the display but does not terminate the appliance-side session behind it - one credential away from a live console again. Exam caveat: set the timeout with the teams, because a value that is too aggressive produces shadow behavior such as keep-alive scripts. Operational check: log into the GUI, leave it idle beyond the configured limit, return, and confirm fresh authentication is demanded.