2.1 Ensure 'displayAuthenticationRealm' is set to 'false'

Information

Configuring displayAuthenticationRealm will ensure that the registry information is not displayed in the login prompt. This will restrict the potential leak of security realm information.

Do not display the user registry information when prompting the user for credentials to avoid showing sensitive information like the LDAP host and port.

Solution

Set the displayAuthenticationRealm attribute in the webAppSecurity element to false in ${server.config.dir}/configDropins/overrides/<any file name>.xml

<webAppSecurity ... displayAuthenticationRealm="false" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Unix

Control ID: f6179c3326f44f785585dc6f8ca0f3dc34992ae5ee38254561f80cafc73659d9