UCF STIG Viewer Logo

The application server must employ cryptographic encryption to protect the integrity and confidentiality of non-local maintenance and diagnostic communications.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35331 SRG-APP-000184-AS-000130 SV-46618r1_rule Medium
Description
Non-local maintenance and diagnostic activities are those activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network. Application servers provide an HTTP-oriented remote management capability that is used for managing the application server as well as uploading and deleting applications that are hosted on the app server. Application servers need to ensure the communication channels used to remotely access the system utilize cryptographic mechanisms such as TLS.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43699r1_chk )
Review the AS configuration to determine if the system is configured to utilize cryptographic encryption like TLS for non-local maintenance connections. If the AS does not utilize cryptographic encryption, this is a finding.
Fix Text (F-39877r1_fix)
Configure the AS to use cryptographic encryption to protect non-local maintenance session integrity and confidentiality.