2.6 - Set check Roles and Policies to all Web applications and EJBs

Information

Set the 'Check Roles and Policies' setting to [All Web applications and EJBs].

Without checking all web applications and EJBs, roles and policies will not be enforced for the entire domain, leaving a malicious user opportunity to gain unauthorized access.

Solution

To enable 'Check Roles and Policies' follow the steps specified below:
1. Login to the Administration Console.
2. In the Change Center, click Lock & Edit.
3. In the left pane, select the Domain name.
4. Select Security Realms > Name of the active Security Realm.
5. Select Configuration > General tab.
6. Select Advanced.
7. Set the 'Check Roles and Policies' to [All Web applications and EJBs], click Save.

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-9

Plugin: Unix

Control ID: 85a9e4ccadf15044b97f8d34cfcd7b0d04de731b66036f57222f6a3a92540029