1.7 Declare an EJB authorization policy for deployed applications

Information

When configuring your application specific security policy, you must declare one (or more) of the following authorization modules in the security domain <policy-module> element.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Applications deploying their own security policies must specify one of the following <policy-module> within their 'code' attributes:

<application-policy name="demo">
<authorization>
<policy-module code="org.JBoss.security.authorization.modules.JACCAuthorizationModule"></policy-module>
</authorization>
</application-policy>

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, 800-53|AC-4, CAT|II

Plugin: Unix

Control ID: 65834416a0eb6184c4560a2c1b3302eff5f31e37911aeba1e5047e86121ca5a0