4.3.8 Ensure 'httpsRequired' is set to 'true' in OIDC Relying Party (RP)

Information

HTTPS protocol protects the integrity and confidentiality of data between the client and the server.

Encrypting the communication between the OpenID Connect relying part and the OpenID Connect server provider using HTTPS protects sensitive information.

Solution

Add the httpsRequired attribute to the openidConnectClient element to ${server.config.dir}/configDropins/overrides/*.xml and set it to true to ensure that security transport is used for JSON Web Tokens.

<openidConnectClient httpsRequired="true" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Unix

Control ID: 01460ad25121912ddddbd89c904feb738dfb08c63479a91ba165d1095f72abed