19 - Cluster Authentication

Information

If a messaging cluster is used, authentication must be in place to prevent unauthorized nodes joining the cluster pool.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Setup you password in the <hornetq-server> element:

<hornetq-server>
....
<cluster-user>myuser</cluster-user>
<cluster-password>${jboss.messaging.cluster.password:mypass}</cluster-password>
</hornetq-server>

See Also

https://docs.jboss.org/author/display/AS72/Hardening+Guidelines

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(7)

Plugin: Unix

Control ID: 9f116c2fe1efa353ceecdd9ec8fc136080f87572301a791fe4d8546dfec34838