Information
The LTPA keys are generated using a password, if a password is not provided, then a default password is used.
The LTPA password should be customized to avoid using the default password.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Add a custom encrypted password to the keysPassword attribute on the ltpa element in the
Liberty configuration
.
<ltpa keysPassword="{aes}AE/PrLc9wshAKURioFvxb41SrVbsWjZTZ8lv72ioH3yMlJN4RQj3A9aT3ev396oYRw==" >