DISA STIGS Viewer

The WebSphere Application Server must authenticate all network-connected endpoint devices before establishing any connection.

Overview

Finding ID Version Rule ID IA Controls Severity
V-81333 WBSP-AS-001110 SV-96047r1_rule   Medium
Description
STIG Date
IBM WebSphere Traditional V9.x Security Technical Implementation Guide 2018-08-24

Details

Check Text (C-81037r2_chk)
Review System Security Plan documentation.

Identify mutual authentication connection requirements.

From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration.

Select each [NodeDefaultSSLSettings] then go to Quality of Protection (QoP) Settings.

If "Client authentication" is not set according to the security plan, this is a finding.
Fix Text (F-88117r1_fix)
From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration.

For each [NodeDefaultSSLSettings] select Quality of Protection (QoP) Settings.

Set "Client authentication" according to the security plan.