UCF STIG Viewer Logo

The application server, when hosting mobile applet code must be configured to host only digitally signed mobile code.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35371 SRG-APP-000208-AS-000145 SV-46658r1_rule Medium
Description
Mobile code technologies include: Java, JavaScript, ActiveX, PDF, Postscript, Shockwave movies, Flash animations, and VBScript. Usage restrictions and implementation guidance apply to both the selection and use of mobile code installed on organizational servers and mobile code downloaded and executed on individual workstations. DoDI 8552.01 policy pertains to the use of mobile code technologies within DoD information systems. Application servers must meet policy requirements regarding the deployment and/or use of mobile code. This includes digitally signing applets in order to provide a means for the client to establish application authenticity.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43734r1_chk )
Review the AS configuration to determine if hosted applets are digitally signed as per mobile code policy. If the AS is not configured to digitally sign hosted mobile code applets, this is a finding.
Fix Text (F-39917r1_fix)
Configure the AS to digitally sign hosted mobile code applets as per DoD policy