The Security Token Service application files must be verified for their integrity.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-256752
VCST-70-000008
SV-256752r889226_rule
Medium
Description
Verifying the Security Token Service application code is unchanged from its shipping state is essential for file validation and nonrepudiation of the Security Token Service. There is no reason the MD5 hash of the RPM original files should be changed after installation, excluding configuration files.
Satisfies: SRG-APP-000131-WSR-000051, SRG-APP-000357-WSR-000150