SV-222931r615938_rule
V-222931
SRG-APP-000033-AS-000024
TCAT-AS-000060
CAT I
10
From the Tomcat server as a privileged user, run the following command:
sudo keytool -storepasswd
When prompted for the keystore password, select a strong password, minimum 10 characters, mixed case alpha-numeric.
Document the password and store in a secured location that is only accessible to authorized personnel.
From the Tomcat server console, run the following command to check the keystore:
sudo keytool -list -v
When prompted for the keystore password type "changeit" sans quotes.
If the contents of the keystore are displayed, this is a finding.
V-222931
False
TCAT-AS-000060
From the Tomcat server console, run the following command to check the keystore:
sudo keytool -list -v
When prompted for the keystore password type "changeit" sans quotes.
If the contents of the keystore are displayed, this is a finding.
M
4094