1.19 - Remove, rename, or comment out the default user accounts from production servers - 'jbossws-users.properties - kermit'

Information

Remove, rename, or comment out the default user accounts defined in .properties files and login-config.xml

Solution

Remove, rename, or comment out the default user accounts in the default <application-policy> elements located within the configuration file: JBOSS_HOME/server/@[email protected]/conf/props/jbossws-users.properties

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5e., CAT|II

Plugin: Unix

Control ID: 28842c6a3a37422e88e2fa3217f8830d9a253a9c1017ead14e1029c25dbb3024