Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-19697 | APP3840 | SV-21838r1_rule | DCSQ-1 | Medium |
Description |
---|
UDDI repositories must provide the capability to support digital signatures. Without the capability to support digital signatures, web service users cannot verify the integrity of the UDDI registry. |
STIG | Date |
---|---|
Application Security and Development STIG | 2014-04-03 |
Check Text ( C-24094r1_chk ) |
---|
If the application does not utilize UDDI registries, this check is not applicable. Ask the application representative for design document and verify the version of the UDDI registry used. UDDI Version 3.0 and above repositories supports digital signatures for web services. 1) If the UDDI registry is not Version 3 or above, this is a finding. |
Fix Text (F-23051r1_fix) |
---|
UDDI repository does not support digital signature. |