5.2.3 Ensure 'identityAssertionTypes' is specified to the correct identity tokens in CSIv2 Attribute Layer - review/Zech

Information

The CSIv2 Attribute policy configures security at the Attribute layer when accessing EJB applications using RMI/IIOP.

The identityAssertionTypes attribute of the attribute layer is set to specify the identity token types that the server supports.

Solution

Set the identityAssertionEnabled attribute to true and identityAssertionTypes to ITTX509CertChain, ITTDistinguishedName in ORB > serverPolicy.csiv2 > layers > authenticationLayer in the ${server.config.dir}/configDropins/overrides/<any file name>.xml

<orb id="defaultOrb">
<clientPolicy.csiv2>
<layers>
<attributeLayer identityAssertionEnabled="true" identityAssertionTypes="ITTX509CertChain, ITTDistinguishedName"/>
</layers>
</clientPolicy.csiv2>
</orb>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(8), CSCv7|9.5

Plugin: Unix

Control ID: b26a09f0b369f514eb4f0f3d114fe3bba31bfc38a005b000138db7db04647099