6.1 Ensure 'HttpsToken' is set in WS-Security policy

Information

Protect JAX-WS Web services applications by enabling HTTPS secure transport in WS-Security policy.Enabling HTTPS secure transport in WS-Security policy protects JAX-WS web services.Enable HTTPS for secure communications.

Using TLS to protect the JAX-WS Web services applications will provide additional protection which may not be provided by SOAP message level security.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Add HttpsToken as seen in the example to wsdl or policy attachment files for each web service.

<wsp:Policy ...>
...
<sp:TransportBinding>
<wsp:Policy>
<sp:TransportToken>
<wsp:Policy>
<sp:HttpsToken />
</wsp:Policy>
</sp:TransportToken>
...
</wsp:Policy>
</sp:TransportBinding>
</wsp:Policy>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-7, 800-53|CP-6, 800-53|CP-7, 800-53|PL-8, 800-53|PM-7, 800-53|SA-8, 800-53|SC-7, CSCv7|11.1

Plugin: Unix

Control ID: 7cd764415f9e727c66911dc5ffa189cd1b097671ac81ea3db15e39e0ece6183e