1.7 Declare an EJB authorization policy for deployed applications

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

When configuring your application specific security policy, you must declare one (or more) of the following authorization modules in the security domain <policy-module> element.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Applications deploying their own security policies must specify one of the following <policy-module> within their 'code' attributes:

<application-policy name="demo">
<authorization>
<policy-module code="org.JBoss.security.authorization.modules.JACCAuthorizationModule"></policy-module>
</authorization>
</application-policy>

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, 800-53|AC-4, CAT|II

Plugin: Unix

Control ID: 65834416a0eb6184c4560a2c1b3302eff5f31e37911aeba1e5047e86121ca5a0