JBOS-AS-000075 - JBoss management interfaces must be secured - http-interface

Information

JBoss utilizes the concept of security realms to secure the management interfaces used for JBoss server administration. If the security realm attribute is omitted or removed from the management interface definition, access to that interface is no longer secure. The JBoss management interfaces must be secured.

Solution

Identify the security realm used for management of the system. By default, this is called 'Management Realm'.

If a management security realm is not already available, reference the Jboss EAP 6.3 system administration guide for instructions on how to create a security realm for management purposes. Create the management realm, and assign authentication and authorization access restrictions to the management realm.

Assign the management interfaces to the management realm.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_JBoss_EAP_6-3_V2R3_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|I, CCI|CCI-000213, Rule-ID|SV-213502r615939_rule, STIG-ID|JBOS-AS-000075, STIG-Legacy|SV-76719, STIG-Legacy|V-62229, Vuln-ID|V-213502

Plugin: Unix

Control ID: bc540cf41999d4ac84c2e33a907d4c7ab5aaabe69e81a501aae9010fb54460dd