STIGQter STIGQter: STIG Summary: JBoss Enterprise Application Platform 6.3 Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

JBoss must be configured to use DoD PKI-established certificate authorities for verification of the establishment of protected sessions.

DISA Rule

SV-213545r615939_rule

Vulnerability Number

V-213545

Group Title

SRG-APP-000427-AS-000264

Rule Version

JBOS-AS-000625

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Locate the cacerts file for the JVM. This can be done using the appropriate find command for the OS and change to the directory where the cacerts file is located.

Remove the certificates that have a CA that is non-DoD approved, and import DoD CA-approved certificates.

Check Contents

Locate the cacerts file for the JVM. This can be done using the appropriate find command for the OS and change to the directory where the cacerts file is located.

To view the certificates stored within this file, execute the java command "keytool -list -v -keystore ./cacerts".
Verify that the Certificate Authority (CA) for each certificate is DoD-approved.

If any certificates have a CA that are not DoD-approved, this is a finding.

Vulnerability Number

V-213545

Documentable

False

Rule Version

JBOS-AS-000625

Severity Override Guidance

Locate the cacerts file for the JVM. This can be done using the appropriate find command for the OS and change to the directory where the cacerts file is located.

To view the certificates stored within this file, execute the java command "keytool -list -v -keystore ./cacerts".
Verify that the Certificate Authority (CA) for each certificate is DoD-approved.

If any certificates have a CA that are not DoD-approved, this is a finding.

Check Content Reference

M

Target Key

3987

Comments