3.1 Ensure JMX Console is either secured or removed - 'java:/jaas/jmx-console = true' - jmx-console.war

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The JMX Console application must be secured so it is accessible by trusted administrators only. If this condition is not met, the application must be removed (deleted) from deployment.

Solution

Finally, configure the usersProperties defined in the application policy to manage accounts. Example editing JBOSS_HOME/server/@PROFILE@/conf/props/jmx-console-users.properties:

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|I, CSCv6|9.1

Plugin: Unix

Control ID: ba45d19dbb73bea6e0480e8b053e0ffd6b05f7bd0fca6e3682cbb2b3197ed606