| Checked | Name | Title |
|---|---|---|
| ☐ | SV-222926r960735_rule | The number of allowed simultaneous sessions to the manager application must be limited. |
| ☐ | SV-222928r960762_rule | HTTP Strict Transport Security (HSTS) must be enabled. |
| ☐ | SV-222930r960765_rule | AccessLogValve must be configured for each application context. |
| ☐ | SV-222931r1137578_rule | Default password for keystore must be changed. |
| ☐ | SV-222932r1137578_rule | Cookies must have secure flag set. |
| ☐ | SV-222933r1137578_rule | Cookies must have http-only flag set. |
| ☐ | SV-222934r1137578_rule | DefaultServlet must be set to readonly for PUT and DELETE. |
| ☐ | SV-222935r1137578_rule | Connectors must be secured. |
| ☐ | SV-222937r960879_rule | Tomcat servers behind a proxy or load balancer must log client IP. |
| ☐ | SV-222938r960882_rule | AccessLogValve must be configured per each virtual host. |
| ☐ | SV-222939r960894_rule | Date and time of events must be logged. |
| ☐ | SV-222940r960897_rule | Remote hostname must be logged. |
| ☐ | SV-222941r960897_rule | HTTP status code must be logged. |
| ☐ | SV-222942r960897_rule | The first line of request must be logged. |
| ☐ | SV-222943r960930_rule | $CATALINA_BASE/logs folder permissions must be set to 750. |
| ☐ | SV-222944r960930_rule | Files in the $CATALINA_BASE/logs/ folder must have their permissions set to 640. |
| ☐ | SV-222945r960933_rule | Files in the $CATALINA_BASE/conf/ folder must have their permissions set to 640. |
| ☐ | SV-222946r960933_rule | $CATALINA_BASE/conf folder permissions must be set to 750. |
| ☐ | SV-222947r960936_rule | Jar files in the $CATALINA_HOME/bin/ folder must have their permissions set to 640. |
| ☐ | SV-222948r960939_rule | $CATALINA_HOME/bin folder permissions must be set to 750. |
| ☐ | SV-222949r960960_rule | Tomcat user UMASK must be set to 0027. |
| ☐ | SV-222950r960963_rule | Stack tracing must be disabled. |
| ☐ | SV-222951r960963_rule | The shutdown port must be disabled. |
| ☐ | SV-222952r1135497_rule | Unapproved connectors must be disabled. |
| ☐ | SV-222953r960963_rule | DefaultServlet debug parameter must be disabled. |
| ☐ | SV-222954r960963_rule | DefaultServlet directory listings parameter must be disabled. |
| ☐ | SV-222955r960963_rule | The deployXML attribute must be set to false in hosted environments. |
| ☐ | SV-222956r960963_rule | Autodeploy must be disabled. |
| ☐ | SV-222957r960963_rule | xpoweredBy attribute must be disabled. |
| ☐ | SV-222958r960963_rule | Example applications must be removed. |
| ☐ | SV-222959r960963_rule | Tomcat default ROOT web application must be removed. |
| ☐ | SV-222960r960963_rule | Documentation must be removed. |
| ☐ | SV-222961r1043177_rule | Applications in privileged mode must be approved by the ISSO. |
| ☐ | SV-222962r1051118_rule | Tomcat management applications must use LDAP realm authentication. |
| ☐ | SV-222963r960972_rule | JMX authentication must be secured. |
| ☐ | SV-222964r1016511_rule | TLS must be enabled on JMX. |
| ☐ | SV-222965r961029_rule | LDAP authentication must be secured. |
| ☐ | SV-222966r985891_rule | DOD root CA certificates must be installed in Tomcat trust store. |
| ☐ | SV-222967r985893_rule | Keystore file must be protected. |
| ☐ | SV-222968r961050_rule | Tomcat must use FIPS-validated ciphers on secured connectors. |
| ☐ | SV-222969r1137579_rule | Access to JMX management interface must be restricted. |
| ☐ | SV-222970r1137579_rule | Access to Tomcat manager application must be restricted. |
| ☐ | SV-222971r1136930_rule | Tomcat servers must mutually authenticate proxy or load balancer connections. |
| ☐ | SV-222973r1043180_rule | Tomcat must be configured to limit data exposure between applications. |
| ☐ | SV-222974r961122_rule | Clusters must operate on a trusted network. |
| ☐ | SV-222975r961167_rule | ErrorReportValve showServerInfo must be set to false. |
| ☐ | SV-222976r961170_rule | Default error pages for manager application must be customized. |
| ☐ | SV-222977r961170_rule | ErrorReportValve showReport must be set to false. |
| ☐ | SV-222979r1043182_rule | Idle timeout for the management application must be set to 10 minutes. |
| ☐ | SV-222980r961278_rule | LockOutRealms must be used for management of Tomcat. |
| ☐ | SV-222981r961281_rule | LockOutRealms failureCount attribute must be set to 5 failed logins for admin users. |
| ☐ | SV-222982r961281_rule | LockOutRealms lockOutTime attribute must be set to 600 seconds (10 minutes) for admin users. |
| ☐ | SV-222983r961353_rule | Tomcat user account must be set to nologin. |
| ☐ | SV-222984r961353_rule | Tomcat user account must be a non-privileged user. |
| ☐ | SV-222985r961362_rule | Application user name must be logged. |
| ☐ | SV-222986r961461_rule | $CATALINA_HOME folder must be owned by the root user, group tomcat. |
| ☐ | SV-222987r961461_rule | $CATALINA_BASE/conf/ folder must be owned by root, group tomcat. |
| ☐ | SV-222988r961461_rule | $CATALINA_BASE/logs/ folder must be owned by tomcat user, group tomcat. |
| ☐ | SV-222989r961461_rule | $CATALINA_BASE/temp/ folder must be owned by tomcat user, group tomcat. |
| ☐ | SV-222990r961461_rule | $CATALINA_BASE/temp folder permissions must be set to 750. |
| ☐ | SV-222991r961461_rule | $CATALINA_BASE/work/ folder must be owned by tomcat user, group tomcat. |
| ☐ | SV-222993r985888_rule | Multifactor certificate-based tokens (CAC) must be used when accessing the management interface. |
| ☐ | SV-222994r961596_rule | Certificates in the trust store must be issued/signed by an approved CA. |
| ☐ | SV-222995r961620_rule | The application server, when categorized as a high availability system within RMF, must be in a high-availability (HA) cluster. |
| ☐ | SV-222996r1067548_rule | Tomcat server must be patched for security vulnerabilities. |
| ☐ | SV-222997r1016518_rule | AccessLogValve must be configured for Catalina engine. |
| ☐ | SV-222998r1193096_rule | Changes to $CATALINA_HOME/bin/ folder must be logged. |
| ☐ | SV-222999r1193098_rule | Changes to $CATALINA_BASE/conf/ folder must be logged. |
| ☐ | SV-223000r1193100_rule | Changes to $CATALINA_HOME/lib/ folder must be logged. |
| ☐ | SV-223001r1137585_rule | Application servers must use NIST-approved or NSA-approved key management technology and processes. |
| ☐ | SV-223002r961863_rule | STRICT_SERVLET_COMPLIANCE must be set to true. |
| ☐ | SV-223003r1135503_rule | RECYCLE_FACADES must be set to true. |
| ☐ | SV-223004r1135506_rule | ALLOW_BACKSLASH must be set to false. |
| ☐ | SV-223005r1135509_rule | ENFORCE_ENCODING_IN_GET_WRITER must be set to true. |
| ☐ | SV-223006r961863_rule | Tomcat users in a management role must be approved by the ISSO. |
| ☐ | SV-223007r961863_rule | Hosted applications must be documented in the system security plan. |
| ☐ | SV-223008r961863_rule | Connectors must be approved by the ISSO. |
| ☐ | SV-223009r961863_rule | Connector address attribute must be set. |
| ☐ | SV-223010r985887_rule | The application server must alert the system administrator (SA) and information system security offer (ISSO), at a minimum, in the event of a log processing failure. |