SV-213499r615939_rule
V-213499
SRG-APP-000033-AS-000024
JBOS-AS-000040
CAT II
10
Document approved management users and their roles. Configure the application server to use RBAC and ensure users are placed into the appropriate roles.
Review the mgmt-users.properties file. Also review the <management /> section in the standalone.xml or domain.xml configuration files. The relevant xml file will depend on if the JBoss server is configured in standalone or domain mode.
Ensure all users listed in these files are approved for management access to the JBoss server and are in the appropriate role.
For domain configurations:
<JBOSS_HOME>/domain/configuration/mgmt-users.properties.
<JBOSS_HOME>/domain/configuration/domain.xml
For standalone configurations:
<JBOSS_HOME>/standalone/configuration/mgmt-users.properties.
<JBOSS_HOME>/standalone/configuration/standalone.xml
If the users listed are not in the appropriate role, this is a finding.
V-213499
False
JBOS-AS-000040
Review the mgmt-users.properties file. Also review the <management /> section in the standalone.xml or domain.xml configuration files. The relevant xml file will depend on if the JBoss server is configured in standalone or domain mode.
Ensure all users listed in these files are approved for management access to the JBoss server and are in the appropriate role.
For domain configurations:
<JBOSS_HOME>/domain/configuration/mgmt-users.properties.
<JBOSS_HOME>/domain/configuration/domain.xml
For standalone configurations:
<JBOSS_HOME>/standalone/configuration/mgmt-users.properties.
<JBOSS_HOME>/standalone/configuration/standalone.xml
If the users listed are not in the appropriate role, this is a finding.
M
3987