7.2 Ensure the 'hostNameIncludeList attribute' is set to a whitelist of host names

Information

Host names can be allowed or blocked from creating inbound TCP connections to different HTTP endpoints.

Defining an IP address include list allows only wanted inbound connections.

Solution

Add the hostNameIncludeList attribute to all tcpOptions elements to ${server.config.dir}/configDropins/overrides/*.xml and set to comma-separated list of host names.

<tcpOptions hostNameIncludeList="*.def.com,sample.here.com" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(8), CSCv7|9.5

Plugin: Unix

Control ID: 26f9a8074ca281ef3130e790c22e00efa972844277599bfab9ca0dbb399f6aaa