SV-222984r615938_rule
V-222984
SRG-APP-000340-AS-000185
TCAT-AS-001060
CAT II
10
From the Tomcat server, create a tomcat user by adding a new non-privileged user OS account with the following command:
sudo useradd tomcat
Edit the systemd tomcat.service file or create one if it does not exist. Use the new "tomcat" user account by setting; USER=tomcat
Location of the file should be /etc/systemd/system/tomcat.service.
Enable the Tomcat service:
sudo restorecon /etc/systemd/system/tomcat.service
sudo chmod 644 /etc/systemd/system/tomcat.service
sudo systemctl enable tomcat.service
Start Tomcat:
sudo systemctl start tomcat
Run the following command to identify the Tomcat process UID:
ps -ef | { head -1; grep catalina; } | cut -f1 -d" "
Run the following command to obtain the OS user ID tied to the Tomcat process:
cat /etc/passwd|grep -i <UID>|cut -f3 -d:
If the user ID field of the passwd file is set to < 1000 or = 0, this is a finding.
V-222984
False
TCAT-AS-001060
Run the following command to identify the Tomcat process UID:
ps -ef | { head -1; grep catalina; } | cut -f1 -d" "
Run the following command to obtain the OS user ID tied to the Tomcat process:
cat /etc/passwd|grep -i <UID>|cut -f3 -d:
If the user ID field of the passwd file is set to < 1000 or = 0, this is a finding.
M
4094