Apache Tomcat Application Server 9 Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000435-AS-000069
Group -
The application server, when categorized as a high availability system within RMF, must be in a high-availability (HA) cluster.
A MAC I system is a system that handles data vital to the organization's operational readiness or effectiveness of deployed or contingency forces. A MAC I system must maintain the highest level of ...Rule Medium Severity -
SRG-APP-000435-AS-000163
Group -
SRG-APP-000495-AS-000220
Group -
SRG-APP-000504-AS-000229
Group -
Changes to $CATALINA_HOME/bin/ folder must be logged.
The $CATALINA_HOME/bin folder contains startup and control scripts for the Tomcat Catalina server. To provide forensic evidence in the event of file tampering, changes to content in this folder mus...Rule Medium Severity -
SRG-APP-000504-AS-000229
Group -
SRG-APP-000504-AS-000229
Group -
Changes to $CATALINA_HOME/lib/ folder must be logged.
The $CATALINA_HOME/lib folder contains library files for the Tomcat Catalina server. These are in the form of java archive (jar) files. To provide forensic evidence in the event of file tampering, ...Rule Medium Severity -
SRG-APP-000514-AS-000137
Group -
Application servers must use NIST-approved or NSA-approved key management technology and processes.
Class 3 PKI certificates are used for servers and software signing rather than for identifying individuals. Class 4 certificates are used for business-to-business transactions. Utilizing unapproved...Rule Low Severity -
SRG-APP-000516-AS-000237
Group -
SRG-APP-000516-AS-000237
Group -
SRG-APP-000516-AS-000237
Group -
ALLOW_BACKSLASH must be set to false.
When Tomcat is installed behind a proxy configured to only allow access to certain Tomcat contexts (web applications), an HTTP request containing "/\../" may allow attackers to work around the prox...Rule Medium Severity -
SRG-APP-000516-AS-000237
Group -
ENFORCE_ENCODING_IN_GET_WRITER must be set to true.
Some clients try to guess the character encoding of text media when the mandated default of ISO-8859-1 should be used. Some browsers will interpret as UTF-7 when the characters are safe for ISO-885...Rule Medium Severity -
SRG-APP-000516-AS-000237
Group -
Tomcat users in a management role must be approved by the ISSO.
Deploying applications to Tomcat requires a Tomcat user account that is in the "manager-script" role. Any user accounts in a Tomcat management role must be approved by the ISSO.Rule Medium Severity -
SRG-APP-000516-AS-000237
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.