The WebSphere Application Server management interface must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
An XCCDF Rule
Description
<VulnDiscussion>To establish acceptance of system usage policy, a click-through banner at the application server management interface logon is required. The banner shall prevent further activity on the application server unless and until the user executes a positive action to manifest agreement by clicking on a box indicating "OK".</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-95949r1_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Open the file ${WAS_HOME}/properties/login.info.
Follow the instructions in the HTML comment section to create the pre-logon banner.
Enter the Standard DoD Mandatory Notice and Consent banner into the HTML section.