SV-213497r1069475_rule
V-213497
SRG-APP-000033-AS-000024
JBOS-AS-000030
CAT I
10
Enabling the Security Manager in JDK 24 is an error and if using JDK 24, this is not a finding.
For a domain installation:
Enable the respective JAVA_OPTS flag in both the domain.conf and the domain.conf.bat files.
For a standalone installation:
Enable the respective JAVA_OPTS flag in both the standalone.conf and the standalone.conf.bat files.
Enabling the Security Manager in JDK 24 is an error and if using JDK 24, this is not a finding.
Note, Security Manager was deprecated in Java 17 and will be permanently removed in JDK 24.
For additional information: <https://openjdk.org/jeps/486>
To determine if the Java Security Manager is enabled for JBoss, the startup commands must be examined. JBoss can be configured to run in either "domain" or a "standalone" mode. JBOSS_HOME is the variable home directory for the JBoss installation. Use relevant OS commands to navigate the file system.
1. For a managed domain installation, review the domain.conf and domain.conf.bat files:
JBOSS_HOME/bin/domain.conf
JBOSS_HOME/bin/domain.conf.bat
In domain.conf file, ensure there is a JAVA_OPTS flag that loads the Java Security Manager as well as a relevant Java Security policy. Example:
JAVA_OPTS="$JAVA_OPTS -Djava.security.manager -Djava.security.policy==$PWD/server.policy -Djboss.home.dir=/path/to/JBOSS_HOME -Djboss.modules.policy-permissions=true"
In domain.conf.bat file, ensure JAVA_OPTS flag is set. Example:
set "JAVA_OPTS=%JAVA_OPTS% -Djava.security.manager -Djava.security.policy==/path/to/server.policy -Djboss.home.dir=/path/to/JBOSS_HOME -Djboss.modules.policy-permissions=true"
2. For a standalone installation, review the standalone.conf and standalone.conf.bat files:
JBOSS_HOME/bin/standalone.conf
JBOSS_HOME/bin/standalone.conf.bat
In the standalone.conf file, ensure the JAVA_OPTS flag is set. Example:
JAVA_OPTS="$JAVA_OPTS -Djava.security.manager -Djava.security.policy==$PWD/server.policy -Djboss.home.dir=$JBOSS_HOME -Djboss.modules.policy-permissions=true"
In the standalone.conf.bat file, ensure the JAVA_OPTS flag is set. Example:
set "JAVA_OPTS=%JAVA_OPTS% -Djava.security.manager -Djava.security.policy==/path/to/server.policy -Djboss.home.dir=%JBOSS_HOME% -Djboss.modules.policy-permissions=true"
If the security manager is not enabled and a security policy not defined, this is a finding.
V-213497
False
JBOS-AS-000030
Enabling the Security Manager in JDK 24 is an error and if using JDK 24, this is not a finding.
Note, Security Manager was deprecated in Java 17 and will be permanently removed in JDK 24.
For additional information: <https://openjdk.org/jeps/486>
To determine if the Java Security Manager is enabled for JBoss, the startup commands must be examined. JBoss can be configured to run in either "domain" or a "standalone" mode. JBOSS_HOME is the variable home directory for the JBoss installation. Use relevant OS commands to navigate the file system.
1. For a managed domain installation, review the domain.conf and domain.conf.bat files:
JBOSS_HOME/bin/domain.conf
JBOSS_HOME/bin/domain.conf.bat
In domain.conf file, ensure there is a JAVA_OPTS flag that loads the Java Security Manager as well as a relevant Java Security policy. Example:
JAVA_OPTS="$JAVA_OPTS -Djava.security.manager -Djava.security.policy==$PWD/server.policy -Djboss.home.dir=/path/to/JBOSS_HOME -Djboss.modules.policy-permissions=true"
In domain.conf.bat file, ensure JAVA_OPTS flag is set. Example:
set "JAVA_OPTS=%JAVA_OPTS% -Djava.security.manager -Djava.security.policy==/path/to/server.policy -Djboss.home.dir=/path/to/JBOSS_HOME -Djboss.modules.policy-permissions=true"
2. For a standalone installation, review the standalone.conf and standalone.conf.bat files:
JBOSS_HOME/bin/standalone.conf
JBOSS_HOME/bin/standalone.conf.bat
In the standalone.conf file, ensure the JAVA_OPTS flag is set. Example:
JAVA_OPTS="$JAVA_OPTS -Djava.security.manager -Djava.security.policy==$PWD/server.policy -Djboss.home.dir=$JBOSS_HOME -Djboss.modules.policy-permissions=true"
In the standalone.conf.bat file, ensure the JAVA_OPTS flag is set. Example:
set "JAVA_OPTS=%JAVA_OPTS% -Djava.security.manager -Djava.security.policy==/path/to/server.policy -Djboss.home.dir=%JBOSS_HOME% -Djboss.modules.policy-permissions=true"
If the security manager is not enabled and a security policy not defined, this is a finding.
M
3987