5.2.1 Ensure 'sslEnabled' is set to 'true' within the CSIv2 TransportLayer - needsReview/Zech

Information

The CSIv2 Transport policy configures security at the transport layer when accessing EJB applications using RMI/IIOP.

Setting the configuration at the transport layer for RMI/IIOP requests will ensure that the data is passed through the IIOPS secure channel.

Solution

Set the sslEnabled attribute in ORB > clientPolicy.csiv2 > layers > transportLayer to true in the ${server.config.dir}/configDropins/overrides/<any file name>.xml

<orb id="defaultOrb">
<clientPolicy.csiv2>
<layers>
<transportLayer sslEnabled="true"/>
</layers>
</clientPolicy.csiv2>
</orb>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 00446b064c9d0220a6878cce5e20f10e3ec39305773278d236ccc0daee36f2bf