4.3.14 Ensure 'skipResourceOwnerValidation' is set to 'false' in OAuth 2.0

Information

Resource owner validation check validates the resource owner credentials.

Verifying the credentials of the resource owner prevents unauthorized access.

Solution

Add the skipResourceOwnerValidation attribute to the oauthProvider element to ${server.config.dir}/configDropins/overrides/*.xml and set to false to ensure resource owner validation is completed.

<oauthProvider skipResourceOwnerValidation="false" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: Unix

Control ID: f37fe30941566df21ef41ca797a79f2bac9815ad4e93bc5f42791013ae3b3a95