Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35223 | SRG-APP-000131-AS-000091 | SV-46510r1_rule | Medium |
Description |
---|
Organizations may require that critical software be signed with a certificate recognized and approved by the organization. This includes messages that are transferred or read by the AS part of a web services or SOA-oriented application. WS-Security is an extension to the SOAP protocol which provides an integrity and confidentiality enhancement that is not native to the SOAP protocol. WS-Security provides the AS with the capability to sign, validate, and encrypt messages. The AS must validate the digital signature of signed web service messages. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43595r1_chk ) |
---|
Check the AS documentation and configuration to determine if the AS validates digitally signed web service messages. If the AS does not meet this requirement, this is a finding. |
Fix Text (F-39769r1_fix) |
---|
Configure the AS features to validate the digital signature bound to web service messages. |