The WebSphere Application Server must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
Overview
Finding ID | Version | Rule ID | IA Controls | Severity |
V-81341 | WBSP-AS-001120 | SV-96055r1_rule | Medium |
Description |
STIG | Date |
IBM WebSphere Traditional V9.x Security Technical Implementation Guide | 2018-08-24 |
Details
Check Text (C-81047r2_chk) |
Review System Security Plan documentation. Identify mutual authentication connection requirements. From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. Select each [NodeDefaultSSLSettings] then go to Quality of Protection (QoP) Settings. If "Client authentication" is not set according to the security plan, this is a finding. Note: with LDAP registry, the entire DN in the certificate is used to look up LDAP. Filters may be configured. With other registries, only the first attribute after the first "=", e.g., CN=<user> is used. |
Fix Text (F-88125r1_fix) |
From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. For each [NodeDefaultSSLSettings] select Quality of Protection (QoP) Settings. Set "Client authentication" according to the security plan. |