TCAT-AS-001720 - Connectors must be approved by the ISSO.

Information

Connectors are how Tomcat receives requests over a network port, passes them to hosted web applications via HTTP or AJP and then sends back the results to the requestor. A port and a protocol are tied to each connector. Only connectors approved by the ISSO must be installed. ISSO review will consist of validating connector protocol as being secure and required in order for the hosted application to operate. The ISSO will ensure that unnecessary or insecure connector protocols are not enabled. The ISSO will provide documented approval for each connector that will be maintained in the System Security Plan (SSP).

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Document and obtain ISSO approval for the Connectors that are configured on the Tomcat server.

Retain the information in the SSP and present to the auditor in the event of a CCRI.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Tomcat_Application_Server_9_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-223008r961863_rule, STIG-ID|TCAT-AS-001720, STIG-Legacy|SV-111539, STIG-Legacy|V-102599, Vuln-ID|V-223008

Plugin: Unix

Control ID: e013f12950b1bc1b035805c37da3d6a68ada178eaa67ccc72b8423ba6fe55713