UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Remote hostname must be logged.


Overview

Finding ID Version Rule ID IA Controls Severity
V-222940 TCAT-AS-000250 SV-222940r615938_rule Medium
Description
The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface within the /opt/tomcat/server.xml configuration file: The %h pattern code is included in the pattern element and logs the remote hostname. Including the hostname pattern in the log configuration provides useful information about the connecting host that is critical for troubleshooting and forensic investigations.
STIG Date
Apache Tomcat Application Sever 9 Security Technical Implementation Guide 2021-12-27

Details

Check Text ( C-24612r426264_chk )
As an elevated user on the Tomcat server:

Edit the $CATALINA_BASE/conf/server.xml file.

Review all "Valve" elements.

If the pattern= statement does not include %h, this is a finding.

EXAMPLE:
unpackWARs="true" autoDeploy="false">
...
prefix="localhost_access_log" suffix=".txt"
pattern="%h %l %t %u "%r" %s %b" />
...
Fix Text (F-24601r426265_fix)
As a privileged user on the Tomcat server:

Edit the $CATALINA_BASE/conf/server.xml file.

Modify the element(s) nested within the element(s).

Change the AccessLogValve setting to include %h in the pattern= statement.

EXAMPLE:
unpackWARs="true" autoDeploy="false">
...
prefix="localhost_access_log" suffix=".txt"
pattern="%h %l %t %u "%r" %s %b" />
...


Restart the Tomcat server:
sudo systemctl restart tomcat
sudo systemctl daemon-reload