3.6 The JMXInvokerServlet servlet must be configured to prevent unprivileged access using authentication

Information

The jmx-invoker-service.xml is a service that exposes the JMX MBeanServer interface via an RMI compatible interface using the RMI/JRMP detached invoker service. Access control for authenticated users must be configured using the interceptors of either org.jboss.jmx.connector.invoker.RolesAuthorization or org.jboss.jmx.connector.invoker.ExternalizableRolesAuthorization.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, 800-53|AC-6, CAT|I

Plugin: Unix

Control ID: 44cbc1e1907dbf7390887877be79c2a233915b1bcc8a95e858a078e706cf7b19