UCF STIG Viewer Logo

The application server must support and maintain the binding of digital signatures on information in transmission.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35080 SRG-APP-000008-AS-000005 SV-46367r1_rule Medium
Description
Digital signatures enable the system to verify the integrity of the signed object and authenticate the object's signatory. Failure to maintain the binding of digital signatures on software components and applications when they are transmitted across the network makes it more likely that an adversary could modify or replace those objects when the software is executed. The bindings enable the operating system to verify the software's integrity and source just before the execution process. In order for the signature to be present at execution, it must be bound before or during transmission. If the application server does not maintain the data security attributes when it transmits the data, there is a risk of data compromise.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43467r3_chk )
Review system documentation to determine if the AS binds a digital signature to software and/or messages when they are transmitted. If these actions are not performed, this is a finding.
Fix Text (F-39631r4_fix)
Configure the AS to digitally sign software and/or messages before or during transmission.