4.3.13 Ensure 'httpsRequired' is set to 'true' in OAuth 2.0

Information

HTTPS protocol protects the integrity and confidentiality of data between the client and the server.

Encrypting communication between the OAuth client and the provider and using HTTPS protects sensitive information.

Solution

Add the httpsRequired attribute to the oauthProvider element to ${server.config.dir}/configDropins/overrides/*.xml and set to true to ensure secure transport with a client.

<oauthProvider httpsRequired="true" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Unix

Control ID: 0cb97c809cb0e71a1f7b5848281fb41df1be0e4280a7bb3bb9eec599691d90fb