4.3.15 Ensure 'httpsRequired' is set to 'true' in SAML

Information

HTTPS protocol protects the integrity and confidentiality of data between the client and the server.

Transport communication accessing a SAML WebSSO service provider end point should be secured with HTTPS (TLS) to protect sensitive information.

Solution

Add the httpsRequired attribute to all samlWebSso20 elements to ${server.config.dir}/configDropins/overrides/*.xml and set it to true

<samlWebSso20 ...
httpsRequired="true"
/>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Unix

Control ID: b989544e22af99c37a1e1f41dfbc686ed1dcacccf563abf0c9d0c6e7f14ebc37