Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-2249 | WG230 A22 | SV-33023r1_rule | EBRU-1 | High |
Description |
---|
Logging in to a web server via an unencrypted protocol or service, to perform updates and maintenance, is a major risk. In all such cases, user accounts and passwords are passed in the plain text. An encrypted protocol or service must be used for remote access for remote access to web administration tasks. Another alternative is to administer the web server from the console, which implies physical access to the server. |
STIG | Date |
---|---|
APACHE SITE 2.2 for Unix | 2011-12-12 |
Check Text ( C-33705r1_chk ) |
---|
If web administration is performed remotely the following checks will apply: If administration of the server is performed remotely, it will only be performed securely by system administrators. If web site administration or web application administration has been delegated, those users will be documented and approved by the IAO. Remote administration must be in compliance with any requirements contained within the Unix Server STIGs, and any applicable network STIGs. Remote administration of any kind will be restricted to documented and authorized personnel. All users performing remote administration must be authenticated. All remote sessions will be encrypted and they will utilize TLS 1.0. |
Fix Text (F-2298r3_fix) |
---|
Ensure the web server's administration is only performed over a secure path. |