10.15 Do not resolve hosts on logging valves

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Setting enableLookups to true on Connector will result in a DNS look-ups to obtain the host name of the remote client before logging any information. This uses additional resources when logging.

Rationale:

Allowing enableLookups adds additional overhead to resolve the host name of a remote client which is rarely needed.

Solution

In Connector elements, set the enableLookups attribute to false or remove it.

<Connector ... enableLookups='false' />

Default Value:

By default, DNS lookups are disabled.

References:

https://tomcat.apache.org/tomcat-9.0-doc/config/valve.html

https://tomcat.apache.org/tomcat-9.0-doc/config/http.html

See Also

https://workbench.cisecurity.org/files/2509

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|5.1

Plugin: Unix

Control ID: a3687d808c99854ad8255b3c6c9ee3f88dbae4f92c107aedda1e8d277037b68b