2.7 - Set check Roles and Policies to all Web applications and EJBs

Information

Set the 'Check Roles and Policies' setting to [All Web applications and EJBs].

Without checking all web applications and EJBs, roles and policies will not be enforced for the entire domain, leaving a malicious user opportunity to gain unauthorized access.

Solution

To enable 'Check Roles and Policies' follow the steps specified below:
1. Login to the Administration Console.
2. In the Change Center, click Lock & Edit.
3. In the left pane, select the Domain name.
4. Select Security Realms > Name of the active Security Realm.
5. Select Configuration > General tab.
6. Select Advanced.
7. Set the 'Check Roles and Policies' to [All Web applications and EJBs], click Save.

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-9

Plugin: Unix

Control ID: 94bc53b42b5e1abcbbc87210716ddb8247012ee93ca808f5876e8c81ea27bc81