3.1 Ensure JMX Console is either secured or removed - 'java:/jaas/jmx-console = true' - jmx-console.war

Information

The JMX Console application must be secured so it is accessible by trusted administrators only. If this condition is not met, the application must be removed (deleted) from deployment.

Solution

Finally, configure the usersProperties defined in the application policy to manage accounts. Example editing JBOSS_HOME/server/@PROFILE@/conf/props/jmx-console-users.properties:

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|I, CSCv6|9.1

Plugin: Unix

Control ID: ba45d19dbb73bea6e0480e8b053e0ffd6b05f7bd0fca6e3682cbb2b3197ed606