SV-106401r1_rule
V-97297
SRG-APP-000090
ISEC-06-551400
CAT II
10
To add a manager role to the Apache Tomcat Web apps (Manager, Host-Manager), run the ISEC7 integrated installer or use the following manual procedure:
By default there are no users with the manager role assigned. To make use of the manager webapp you need to add a new role and user into the <Drive>:\Program Files\ISEC7 EMM Suite\Tomcat\conf\tomcat-users.xml file.
Login to the ISEC7 EMM Suite server.
Navigate to <Drive>:\Program Files\ISEC7 EMM Suite\Tomcat\conf\
Add a user with the manager role to <Drive>:\Program Files\ISEC7 EMM Suite\Tomcat\conf\tomcat-users.xml
example: <user username="admin" roles="manager-gui,manager-script" ..../>
Save the file.
Verify a manager role has been assigned to the Apache Tomcat Web apps (Manager, Host-Manager).
Login to the ISEC7 EMM Suite server.
Navigate to <Drive>:\Program Files\ISEC7 EMM Suite\Tomcat\conf\
Confirm a user with the manager role to <Drive>:\Program Files\ISEC7 EMM Suite\Tomcat\conf\tomcat-users.xml exists.
example: <user username="admin" roles="manager-gui,manager-script" ..../>
If a manager role has not been assigned to the Apache Tomcat Web apps, this is a finding.
V-97297
False
ISEC-06-551400
Verify a manager role has been assigned to the Apache Tomcat Web apps (Manager, Host-Manager).
Login to the ISEC7 EMM Suite server.
Navigate to <Drive>:\Program Files\ISEC7 EMM Suite\Tomcat\conf\
Confirm a user with the manager role to <Drive>:\Program Files\ISEC7 EMM Suite\Tomcat\conf\tomcat-users.xml exists.
example: <user username="admin" roles="manager-gui,manager-script" ..../>
If a manager role has not been assigned to the Apache Tomcat Web apps, this is a finding.
M
3503