Skip to content

HTTP management session traffic must be encrypted.

An XCCDF Rule

Description

Types of management interfaces utilized by the JBoss EAP application server include web-based HTTP interfaces as well as command line-based management interfaces. In the event remote HTTP management is required, the access must be via HTTPS. This requirement is in conjunction with the requirement to isolate all management access to a restricted network.

ID
SV-213494r960759_rule
Version
JBOS-AS-000010
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Follow the specific instructions in the Red Hat Security Guide for EAP version 6.3 to configure the management console for HTTPS.

This involves the following steps.
1. Create a keystore in JKS format.
2. Ensure the management console binds to HTTPS.
3. Create a new Security Realm.