This will enable session persistance across restarts as described {{{http://tomcat.apache.org/tomcat-7.0-doc/config/manager.html#Special_Features}here}}.
To protect requests and responses you should use HTTPS and configure your Apache Webserver installation to redirect all traffic according to this