Skip to content

JBoss Enterprise Application Platform 6.3 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000172-AS-000120

    Group
  • LDAP enabled security realm value allow-empty-passwords must be set to false.

    Passwords need to be protected at all times, and encryption is the standard method for protecting passwords during transmission. If passwords are not encrypted, they can be plainly read (i.e., cle...
    Rule Medium Severity
  • SRG-APP-000172-AS-000121

    Group
  • JBoss must utilize encryption when using LDAP for authentication.

    Passwords need to be protected at all times, and encryption is the standard method for protecting passwords during transmission. Application servers have the capability to utilize LDAP directories...
    Rule Medium Severity
  • SRG-APP-000176-AS-000125

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules