Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35080 | SRG-APP-000008-AS-000005 | SV-46367r1_rule | Medium |
Description |
---|
Digital signatures enable the system to verify the integrity of the signed object and authenticate the object's signatory. Failure to maintain the binding of digital signatures on software components and applications when they are transmitted across the network makes it more likely that an adversary could modify or replace those objects when the software is executed. The bindings enable the operating system to verify the software's integrity and source just before the execution process. In order for the signature to be present at execution, it must be bound before or during transmission. If the application server does not maintain the data security attributes when it transmits the data, there is a risk of data compromise. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43467r3_chk ) |
---|
Review system documentation to determine if the AS binds a digital signature to software and/or messages when they are transmitted. If these actions are not performed, this is a finding. |
Fix Text (F-39631r4_fix) |
---|
Configure the AS to digitally sign software and/or messages before or during transmission. |