1.27 IBMW-LS-001120

Information

The WebSphere Liberty Server must be configured to use HTTPS only.

GROUP ID: V-250348RULE ID: SV-250348r961635

Transmission of data can take place between the application server and a large number of devices/applications external to the application server. Examples are a web client used by a user, a backend database, a log server, or other application servers in an application server cluster.

Solution

Modify the server.xml file. Enable the ssl-1.0 feature and configure the httpEndpoint settings. The keystores and truststores must also be configured.

<httpEndpoint id="defaultHttpEndpoint" host="localhost" httpPort="${bvt.prop.HTTP_default}" httpsPort="${bvt.prop.HTTP_default.secure}" > <tcpOptions soReuseAddr="true" /> <sslOptions sslRef="testSSLConfig" /> <ssl id="defaultSSLConfig" keyStoreRef="defaultKeyStore" trustStoreRef="defaultKeyStore" serverKeyAlias="default" /> <ssl id="testSSLConfig" keyStoreRef="defaultKeyStore" trustStoreRef="alternateTrustStore" serverKeyAlias="alternateCert" enabledCiphers="AES256-SHA AES128-SHA" />

<keyStore id="defaultKeyStore" password="Liberty"location="${server.config.dir}/resources/security/sslOptions.jks" />

<keyStore id="defaultTrustStore" password="Liberty"location="${server.config.dir}/resources/security/trust.jks" />

<keyStore id="alternateTrustStore" password="Liberty"location="${server.config.dir}/resources/security/optionsTrust.jks" />

<application type="war" id="basicauth" name="basicauth" location="${server.config.dir}/apps/basicauth.war" />

See Also

https://workbench.cisecurity.org/benchmarks/23823