3.5 The JMXInvokerServlet servlet must be configured to prevent unprivileged access using authentication

Information

The jmx-invoker-service.xml is a service that exposes the JMX MBeanServer interface via an RMI compatible interface using the RMI/JRMP detached invoker service. This interface must be made unavailable to unprivileged users which can be done by using the org.jboss.jmx.connector.invoker.AuthenticationInterceptor interceptor for performing identification and authentication using JAAS.

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, 800-53|IA-3, CAT|I

Plugin: Unix

Control ID: ac134659fe272824b92b8723e398764be64870597f553a7ab491ba567adb6f46