Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35331 | SRG-APP-000184-AS-000130 | SV-46618r1_rule | Medium |
Description |
---|
Non-local maintenance and diagnostic activities are those activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network. Application servers provide an HTTP-oriented remote management capability that is used for managing the application server as well as uploading and deleting applications that are hosted on the app server. Application servers need to ensure the communication channels used to remotely access the system utilize cryptographic mechanisms such as TLS. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43699r1_chk ) |
---|
Review the AS configuration to determine if the system is configured to utilize cryptographic encryption like TLS for non-local maintenance connections. If the AS does not utilize cryptographic encryption, this is a finding. |
Fix Text (F-39877r1_fix) |
---|
Configure the AS to use cryptographic encryption to protect non-local maintenance session integrity and confidentiality. |