SV-213532r615939_rule
V-213532
SRG-APP-000172-AS-000120
JBOS-AS-000305
CAT II
10
Configure the LDAP Security Realm using default settings that sets "allow-empty-values" to false. LDAP Security Realm creation is described in section 11.9 -Add an LDAP Security Realm in the JBoss_Enterprise_Application_Platform-6.3-Administration_and_Configuration_Guide-en-US document.
Log on to the OS of the JBoss server with OS permissions that allow access to JBoss.
Using the relevant OS commands and syntax, cd to the <JBOSS_HOME>/bin/ folder.
Run the jboss-cli script.
Connect to the server and authenticate.
Run the command:
"ls /core-service=management/security-realm=ldap_security_realm/authentication=ldap"
If "allow-empty-passwords=true", this is a finding.
V-213532
False
JBOS-AS-000305
Log on to the OS of the JBoss server with OS permissions that allow access to JBoss.
Using the relevant OS commands and syntax, cd to the <JBOSS_HOME>/bin/ folder.
Run the jboss-cli script.
Connect to the server and authenticate.
Run the command:
"ls /core-service=management/security-realm=ldap_security_realm/authentication=ldap"
If "allow-empty-passwords=true", this is a finding.
M
3987