1.1 Remove extraneous files and directories (CONFIG_DIR/Catalina/localhost/host-manager.xml) | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
1.2 Disable Unused Connectors | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
3.1 Set a nondeterministic Shutdown command value | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | ACCESS CONTROL |
3.1 Set a nondeterministic Shutdown command value | CIS Apache Tomcat 11 v1.0.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
3.1 Set a nondeterministic Shutdown command value. | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
4.5 Restrict access to Tomcat temp directory | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | ACCESS CONTROL |
4.6 Restrict access to Tomcat binaries directory | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | ACCESS CONTROL |
4.6 Restrict access to Tomcat binaries directory | CIS Apache Tomcat 10.1 v1.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
4.6 Restrict access to Tomcat binaries directory | CIS Apache Tomcat 11 v1.0.0 L1 | Unix | CONFIGURATION MANAGEMENT |
4.8 Restrict access to Tomcat catalina.properties | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | ACCESS CONTROL |
4.8 Restrict access to Tomcat catalina.properties | CIS Apache Tomcat 10.1 v1.1.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
4.9 Restrict access to Tomcat catalina.policy | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | ACCESS CONTROL |
4.10 Restrict access to Tomcat context.xml | CIS Apache Tomcat 11 v1.0.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
4.12 Restrict access to Tomcat server.xml | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | ACCESS CONTROL |
5.1 Use secure Realms | CIS Apache Tomcat 10.1 v1.1.0 L2 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
5.2 Use LockOut Realms | CIS Apache Tomcat 10 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
5.2 Use LockOut Realms | CIS Apache Tomcat 10.1 v1.1.0 L2 | Unix | CONFIGURATION MANAGEMENT |
6.1 Setup Client-cert Authentication | CIS Apache Tomcat 10 L2 v1.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
6.1 Setup Client-cert Authentication | CIS Apache Tomcat 8 L2 v1.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
6.2 Ensure SSLEnabled is set to True for Sensitive Connectors | CIS Apache Tomcat 10.1 v1.1.0 L1 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
6.5 Ensure 'sslProtocol' is Configured Correctly for Secure Connectors | CIS Apache Tomcat 10.1 v1.1.0 L1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
6.6 Control the maximum size of a POST request that will be parsed for parameter | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | |
7.2 Specify file handler in logging.properties (check if java.util.logging.ConsoleHandler logging is enabled in default) | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
7.2 Specify file handler in logging.properties files - check if org.apache.juli.FileHandler exists in default | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
7.2 Specify file handler in logging.properties files - check if org.apache.juli.FileHandler exists in web application | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
7.6 Ensure directory in logging.properties is a secure location | CIS Apache Tomcat 10.1 v1.1.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
7.7 Configure log file size limit (verify java.util.logging.FileHandler.limit is present) | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
8.1 Restrict runtime access to sensitive packages | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | ACCESS CONTROL |
9.2 Disable deploy on startup of applications | CIS Apache Tomcat 10.1 v1.1.0 L2 | Unix | CONFIGURATION MANAGEMENT |
9.2 Disabling auto deployment of applications | CIS Apache Tomcat 10 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
9.2 Disabling auto deployment of applications | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
9.2 Disabling auto deployment of applications | CIS Apache Tomcat 8 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
9.3 Disable deploy on startup of applications | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
9.3 Disable deploy on startup of applications | CIS Apache Tomcat 8 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
10.1 Ensure Web content directory is on a separate partition from the Tomcat system files | CIS Apache Tomcat 11 v1.0.0 L1 | Unix | CONFIGURATION MANAGEMENT, MAINTENANCE |
10.3 Restrict manager application | CIS Apache Tomcat 10.1 v1.1.0 L2 | Unix | ACCESS CONTROL |
10.4 Force SSL when accessing the manager application | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
10.9 Configure connectionTimeout | CIS Apache Tomcat 10 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
10.9 Configure connectionTimeout | CIS Apache Tomcat 10.1 v1.1.0 L2 | Unix | CONFIGURATION MANAGEMENT |
10.10 Configure connectionTimeout | CIS Apache Tomcat 8 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
10.10 Configure maxHttpHeaderSize | CIS Apache Tomcat 10.1 v1.1.0 L2 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
10.11 Configure maxHttpHeaderSize | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
10.12 Force SSL for all applications | CIS Apache Tomcat 8 L2 v1.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
10.15 Do not run applications as privileged | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | ACCESS CONTROL |
10.17 Do not resolve hosts on logging valves | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
10.17 Enable memory leak listener - verify present | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
10.18 Enable memory leak listener (verify present) | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | SYSTEM AND INFORMATION INTEGRITY |
10.18 Setting Security Lifecycle Listener - check for umask present in startup | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
10.18 Setting Security Lifecycle Listener - check for umask uncommented in startup | CIS Apache Tomcat 8 L1 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
10.19 Setting Security Lifecycle Listener (check for umask uncommented in startup) | CIS Apache Tomcat 7 L1 v1.1.0 | Unix | ACCESS CONTROL |