SV-213534r615939_rule
V-213534
SRG-APP-000176-AS-000125
JBOS-AS-000320
CAT II
10
Configure the application server OS file permissions on the corresponding private key to restrict access to authorized accounts or roles.
The default location for the keystore used by the JBoss vault is the <JBOSS_HOME>/vault/ folder.
If a vault keystore has been created, by default it will be in the file: <JBOSS_HOME>/vault/vault.keystore. The file stores a single key, with the default alias vault, which will be used to store encrypted strings, such as passwords, for JBoss EAP.
Browse to the JBoss vault folder using the relevant OS commands.
Review the file permissions and ensure only system administrators and JBoss users are allowed access.
Owner can be full access
Group can be full access
All others must be restricted to execute access or no permission.
If non-system administrators are allowed to access the <JBOSS_HOME>/vault/
folder, this is a finding.
V-213534
False
JBOS-AS-000320
The default location for the keystore used by the JBoss vault is the <JBOSS_HOME>/vault/ folder.
If a vault keystore has been created, by default it will be in the file: <JBOSS_HOME>/vault/vault.keystore. The file stores a single key, with the default alias vault, which will be used to store encrypted strings, such as passwords, for JBoss EAP.
Browse to the JBoss vault folder using the relevant OS commands.
Review the file permissions and ensure only system administrators and JBoss users are allowed access.
Owner can be full access
Group can be full access
All others must be restricted to execute access or no permission.
If non-system administrators are allowed to access the <JBOSS_HOME>/vault/
folder, this is a finding.
M
3987