UCF STIG Viewer Logo

The application server must validate the digital signature of signed web service messages.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35223 SRG-APP-000131-AS-000091 SV-46510r1_rule Medium
Description
Organizations may require that critical software be signed with a certificate recognized and approved by the organization. This includes messages that are transferred or read by the AS part of a web services or SOA-oriented application. WS-Security is an extension to the SOAP protocol which provides an integrity and confidentiality enhancement that is not native to the SOAP protocol. WS-Security provides the AS with the capability to sign, validate, and encrypt messages. The AS must validate the digital signature of signed web service messages.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43595r1_chk )
Check the AS documentation and configuration to determine if the AS validates digitally signed web service messages. If the AS does not meet this requirement, this is a finding.
Fix Text (F-39769r1_fix)
Configure the AS features to validate the digital signature bound to web service messages.