7.1 Ensure the 'hostNameExcludeList' attribute is set to a whitelist of host names

Information

Host names can be allowed or blocked from creating inbound TCP connections to different HTTP endpoints.

Defining an IP address exclude list protects against unwanted inbound connections.

Solution

Add the hostNameExcludeList attribute to all tcpOptions elements to ${server.config.dir}/configDropins/overrides/*.xml and set to comma-separated list of host names.

<tcpOptions hostNameExcludeList="*.abc.com,sample.all.com" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(8), CSCv7|9.5

Plugin: Unix

Control ID: c54a76555ae2ebde0124c18ad12fb7aeb5c5ce129199c1b2860e588a9eb20f73