Item Search

NameAudit NamePluginCategory
2.1 Alter the Advertised server.info StringCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

DISA_STIG_VMware_vSphere_6.7_EAM_Tomcat_v1r4.audit from DISA VMware vSphere 6.7 EAM Tomcat v1r4 STIGDISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix
TCAT-AS-000030 - HTTP Strict Transport Security (HSTS) must be enabled.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL

TCAT-AS-000040 - TLS 1.2 must be used on secured HTTP connectors.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-000050 - AccessLogValve must be configured for each application context.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

TCAT-AS-000060 - Default password for keystore must be changed.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

TCAT-AS-000070 - Cookies must have secure flag set.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL

TCAT-AS-000080 - Cookies must have http-only flag set.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL

TCAT-AS-000100 - Connectors must be secured.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL

TCAT-AS-000180 - AccessLogValve must be configured per each virtual host.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-000260 - HTTP status code must be logged.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-000270 - The first line of request must be logged.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-000360 - $CATALINA_BASE/logs folder permissions must be set to 750.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-000361 - Files in the $CATALINA_BASE/logs/ folder must have their permissions set to 640.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-000370 - Files in the $CATALINA_BASE/conf/ folder must have their permissions set to 640.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

TCAT-AS-000371 - $CATALINA_BASE/conf folder permissions must be set to 750.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

TCAT-AS-000380 - Jar files in the $CATALINA_HOME/bin/ folder must have their permissions set to 640.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-000450 - Tomcat user UMASK must be set to 0027.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000490 - The shutdown port must be disabled.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000500 - Unapproved connectors must be disabled.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000510 - DefaultServlet debug parameter must be disabled.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000540 - Autodeploy must be disabled.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000550 - xpoweredBy attribute must be disabled.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000560 - Example applications must be removed.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000590 - Applications in privileged mode must be approved by the ISSO.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-000610 - JMX authentication must be secured.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

TCAT-AS-000710 - Keystore file must be protected.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

TCAT-AS-000750 - Tomcat must use FIPS-validated ciphers on secured connectors.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-000790 - Access to Tomcat manager application must be restricted.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-000800 - Tomcat servers must mutually authenticate proxy or load balancer connections.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-000860 - Clusters must operate on a trusted network.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-000920 - ErrorReportValve showServerInfo must be set to false.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

TCAT-AS-000930 - Default error pages for manager application must be customized.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

TCAT-AS-000940 - ErrorReportValve showReport must be set to false.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

TCAT-AS-001040 - LockOutRealms lockOutTime attribute must be set to 600 seconds (10 minutes) for admin users.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL

TCAT-AS-001050 - Tomcat user account must be set to nologin.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

ACCESS CONTROL

TCAT-AS-001200 - $CATALINA_HOME folder must be owned by the root user, group tomcat.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-001260 - $CATALINA_BASE/temp/ folder must be owned by tomcat user, group tomcat.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-001280 - $CATALINA_BASE/work/ folder must be owned by tomcat user, group tomcat.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-001430 - Certificates in the trust store must be issued/signed by an approved CA.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-001460 - The application server, when categorized as a high availability system within RMF, must be in a high-availability (HA) cluster.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-001470 - Tomcat server must be patched for security vulnerabilities.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

TCAT-AS-001590 - Changes to $CATALINA_HOME/bin/ folder must be logged.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-001591 - Changes to $CATALINA_BASE/conf/ folder must be logged.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-001640 - Application servers must use NIST-approved or NSA-approved key management technology and processes.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-001690 - ENFORCE_ENCODING_IN_GET_WRITER must be set to true.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-001710 - Hosted applications must be documented in the system security plan.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-001720 - Connectors must be approved by the ISSO.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-001730 - Connector address attribute must be set.DISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

Tomcat foundDISA STIG Apache Tomcat Application Server 9 v3r1 MiddlewareUnix