1.6 Ensure automated configuration updates are disabled

Information

WebSphere Liberty provides the ability to automatically update the server runtime when the configuration changes, without requiring a server restart.

Automatic updates during runtime are very useful during development and test phases. Configuration updates must be carefully controlled in production environments to reduce the possibility that unknown changes or vulnerabilities are deployed to users.

Solution

Add the updateTrigger attribute to the config element in ${server.config.dir}/configDropins/overrides/*.xml and set to mbean or disabled

<config updateTrigger="mbean" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Unix

Control ID: 4dace4ae2fe878108cd3d5ec6311c400b7d089a5908594f4b34d34ce9d097a95