Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35073 | SRG-APP-000006-AS-000002 | SV-46341r1_rule | Medium |
Description |
---|
Digital signatures enable the system to verify the integrity of the signed object and authenticate the object's signatory. Failure to maintain the binding of digital signatures on software components and applications in storage makes it more likely that an adversary could modify or replace those objects. Conversely, the bindings enable the operating system to verify the software's integrity and source with a high degree of assurance whenever necessary. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43460r2_chk ) |
---|
Review system documentation to determine if the AS maintains the binding of digital signatures to software objects when those objects are stored after installation. If these bindings are not maintained, this is a finding. |
Fix Text (F-39625r3_fix) |
---|
Configure the AS to maintain the binding of digital signatures to software objects when those objects are stored after installation. |