The WebSphere Application Server LDAP user registry must be used.
An XCCDF Rule
Description
To assure accountability and prevent unauthorized access, application server users must be uniquely identified and authenticated. This is typically accomplished via the use of a user store which is either local (OS-based) or centralized (LDAP) in nature. To ensure support to the enterprise, the authentication must utilize an enterprise solution.
- ID
- SV-96013r1_rule
- Version
- WBSP-AS-001010
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
In the administrative console, click Security >> Global security.
Under "User account repository", click the "Available realm definitions" drop-down list.
Select "Standalone LDAP" registry.