SV-222963r615938_rule
V-222963
SRG-APP-000149-AS-000102
TCAT-AS-000610
CAT II
10
If using JMX for management of the Tomcat server, start the Tomcat server by adding the following command line flags to the systemd startup scripts in /etc/systemd/system/tomcat.service.
Environment='CATALINA_OPTS -Dcom.sun.management.jmxremote -Dcom.sun.management.jmxremote.authenticate=true -Dcom.sun.management.jmxremote.ssl=true'
sudo systemctl start tomcat
sudo systemctl daemon-reload
From the Tomcat server run the following command:
sudo grep -I jmxremote.authenticate /etc/systemd/system/tomcat.service
sudo ps -ef |grep -i jmxremote
If the results are blank, this is not a finding.
If the results include:
-Dcom.sun.management.jmxremote.authenticate=false, this is a finding.
V-222963
False
TCAT-AS-000610
From the Tomcat server run the following command:
sudo grep -I jmxremote.authenticate /etc/systemd/system/tomcat.service
sudo ps -ef |grep -i jmxremote
If the results are blank, this is not a finding.
If the results include:
-Dcom.sun.management.jmxremote.authenticate=false, this is a finding.
M
4094