The WebSphere Application Server must authenticate all network-connected endpoint devices before establishing any connection.
Overview
Finding ID | Version | Rule ID | IA Controls | Severity |
V-81333 | WBSP-AS-001110 | SV-96047r1_rule | Medium |
Description |
STIG | Date |
IBM WebSphere Traditional V9.x Security Technical Implementation Guide | 2018-08-24 |
Details
Check Text (C-81037r2_chk) |
Review System Security Plan documentation. Identify mutual authentication connection requirements. From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. Select each [NodeDefaultSSLSettings] then go to Quality of Protection (QoP) Settings. If "Client authentication" is not set according to the security plan, this is a finding. |
Fix Text (F-88117r1_fix) |
From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. For each [NodeDefaultSSLSettings] select Quality of Protection (QoP) Settings. Set "Client authentication" according to the security plan. |