3.8 - Host Name Verification should be set

Information

Ensure that the 'Host Name Verification' is set to [BEA Hostname Verifier] on all Servers.

If host name verification is not enabled, a man-in-the-middle attack can occur.

Solution

To set the host name verification follow the steps mentioned below:
1. Login to the Administration Console.
2. In the Change Center, click Lock & Edit.
3. In the left pane select the Domain name > Environment > Servers.
4. For each Server, follow steps 5-8 below.
5. Select the Server name.
6. Select Configuration > SSL.
7. Expand the Advanced portion to locate the 'Hostname Verification' setting.
8. Ensure the [BEA Hostname Verifier] is selected, click Save