10.4 Ensure 'keysPassword' is set to a custom password for ltpa keys

Information

The LTPA keys are generated using a password, if a password is not provided, then a default password is used.

The LTPA password should be customized to avoid using the default password.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Add a custom encrypted password to the keysPassword attribute on the ltpa element in the

Liberty configuration

.

<ltpa keysPassword="{aes}AE/PrLc9wshAKURioFvxb41SrVbsWjZTZ8lv72ioH3yMlJN4RQj3A9aT3ev396oYRw==" >

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.2

Plugin: Unix

Control ID: 392f13735660c87a6f457d4a02167a73884cf108442f6eb2493d1439d1e3abe7