UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The application server must uniquely identify and authenticate users (or processes acting on behalf of users).


Overview

Finding ID Version Rule ID IA Controls Severity
V-35299 SRG-APP-000148-AS-000101 SV-46586r1_rule High
Description
To assure accountability and prevent unauthorized access, AS users must be uniquely identified and authenticated. The application server must uniquely identify and authenticate application server users or processes acting on behalf of users. This is typically accomplished via the use of a user store which is either local (OS based) or centralized (LDAP) in nature.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43668r1_chk )
Review AS documentation and configuration settings to determine if the AS requires the use of individual accounts to identify and authenticate AS users and user processes. If the AS does not meet this requirement, this is a finding.
Fix Text (F-39845r1_fix)
Create and configure the appropriate accounts and align them in their respective roles as identified in the product documentation.