STIGQter STIGQter: STIG Summary:

JBoss Enterprise Application Platform 6.3 Security Technical Implementation Guide

Version: 2

Release: 6 Benchmark Date: 02 Apr 2025

CheckedNameTitle
SV-213494r960759_ruleHTTP management session traffic must be encrypted.
SV-213495r960762_ruleHTTPS must be enabled for JBoss web interfaces.
SV-213496r1069472_ruleJava permissions must be set for hosted applications.
SV-213497r1069475_ruleThe Java Security Manager must be enabled for the JBoss application server.
SV-213498r1028281_ruleThe JBoss server must be configured with Role Based Access Controls.
SV-213499r960792_ruleUsers in JBoss Management Security Realms must be in the appropriate role.
SV-213500r960792_ruleSilent Authentication must be removed from the Default Application Security Realm.
SV-213501r960792_ruleSilent Authentication must be removed from the Default Management Security Realm.
SV-213502r960792_ruleJBoss management interfaces must be secured.
SV-213503r1028283_ruleThe JBoss server must generate log records for access and authentication events to the management interface.
SV-213504r960882_ruleJBoss must be configured to allow only the ISSM (or individuals or roles appointed by the ISSM) to select which loggable events are to be logged.
SV-213505r960888_ruleJBoss must be configured to initiate session logging upon startup.
SV-213506r960891_ruleJBoss must be configured to log the IP address of the remote system connecting to the JBoss system/cluster.
SV-213507r960891_ruleJBoss must be configured to produce log records containing information to establish what type of events occurred.
SV-213508r960894_ruleJBoss Log Formatter must be configured to produce log records that establish the date and time the events occurred.
SV-213509r960897_ruleJBoss must be configured to produce log records that establish which hosted application triggered the events.
SV-213510r960900_ruleJBoss must be configured to record the IP address and port information used by management interface network traffic.
SV-213511r960903_ruleThe application server must produce log records that contain sufficient information to establish the outcome of events.
SV-213512r960906_ruleJBoss ROOT logger must be configured to utilize the appropriate logging level.
SV-213513r960930_ruleFile permissions must be configured to protect log information from any type of unauthorized read access.
SV-213514r960933_ruleFile permissions must be configured to protect log information from unauthorized modification.
SV-213515r960936_ruleFile permissions must be configured to protect log information from unauthorized deletion.
SV-213516r960948_ruleJBoss log records must be off-loaded onto a different system or system component a minimum of every seven days.
SV-213517r960960_rulemgmt-users.properties file permissions must be set to allow access to authorized users only.
SV-213518r960963_ruleJBoss process owner interactive access must be restricted.
SV-213519r960963_ruleGoogle Analytics must be disabled in EAP Console.
SV-213520r960963_ruleJBoss process owner execution permissions must be limited.
SV-213521r960963_ruleJBoss QuickStarts must be removed.
SV-213522r960963_ruleRemote access to JMX subsystem must be disabled.
SV-213523r960963_ruleWelcome Web Application must be disabled.
SV-213524r960963_ruleAny unapproved applications must be removed.
SV-213525r1043177_ruleJBoss application and management ports must be approved by the PPSM CAL.
SV-213526r1051118_ruleThe JBoss Server must be configured to utilize a centralized authentication mechanism such as AD or LDAP.
SV-213527r960972_ruleThe JBoss Server must be configured to use certificates to authenticate admins.
SV-213528r981680_ruleThe JBoss server must be configured to use individual accounts and not generic or shared accounts.
SV-213529r981681_ruleJBoss management Interfaces must be integrated with a centralized authentication mechanism that is configured to manage accounts according to DoD policy.
SV-213530r981682_ruleThe JBoss Password Vault must be used for storing passwords or other sensitive configuration information.
SV-213531r981682_ruleJBoss KeyStore and Truststore passwords must not be stored in clear text.
SV-213532r961029_ruleLDAP enabled security realm value allow-empty-passwords must be set to false.
SV-213533r961029_ruleJBoss must utilize encryption when using LDAP for authentication.
SV-213534r961041_ruleThe JBoss server must be configured to restrict access to the web servers private key to authenticated system administrators.
SV-213535r961095_ruleThe JBoss server must separate hosted application functionality from application server management functionality.
SV-213536r961128_ruleJBoss file permissions must be configured to protect the confidentiality and integrity of application files.
SV-213537r961170_ruleAccess to JBoss log files must be restricted to authorized users.
SV-213538r961281_ruleNetwork access to HTTP management must be disabled on domain-enabled application servers not designated as the domain controller.
SV-213539r961353_ruleThe application server must prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-213540r961362_ruleThe JBoss server must be configured to log all admin activity.
SV-213541r961395_ruleThe JBoss server must be configured to utilize syslog logging.
SV-213542r961461_ruleProduction JBoss servers must not allow automatic application deployment.
SV-213543r981687_ruleProduction JBoss servers must log when failed application deployments occur.
SV-213544r981687_ruleProduction JBoss servers must log when successful application deployments occur.
SV-213545r961596_ruleJBoss must be configured to use DoD PKI-established certificate authorities for verification of the establishment of protected sessions.
SV-213546r961620_ruleThe JBoss server, when hosting mission critical applications, must be in a high-availability (HA) cluster.
SV-213547r961632_ruleJBoss must be configured to use an approved TLS version.
SV-213548r961635_ruleJBoss must be configured to use an approved cryptographic algorithm in conjunction with TLS.
SV-213549r961683_ruleProduction JBoss servers must be supported by the vendor.
SV-213550r961683_ruleThe JRE installed on the JBoss server must be kept up to date.
SV-213551r961800_ruleJBoss must be configured to generate log records when successful/unsuccessful attempts to modify privileges occur.
SV-213552r961812_ruleJBoss must be configured to generate log records when successful/unsuccessful attempts to delete privileges occur.
SV-213553r961824_ruleJBoss must be configured to generate log records when successful/unsuccessful logon attempts occur.
SV-213554r961827_ruleJBoss must be configured to generate log records for privileged activities.
SV-213555r961830_ruleJBoss must be configured to generate log records that show starting and ending times for access to the application server management interface.
SV-213556r961833_ruleJBoss must be configured to generate log records when concurrent logons from different workstations occur to the application server management interface.
SV-213557r961842_ruleJBoss must be configured to generate log records for all account creations, modifications, disabling, and termination events.
SV-213558r961857_ruleThe JBoss server must be configured to use DoD- or CNSS-approved PKI Class 3 or Class 4 certificates.
SV-213559r961860_ruleJBoss servers must be configured to roll over and transfer logs on a minimum weekly basis.
SV-217099r961863_ruleThe JBoss server must be configured to bind the management interfaces to only management networks.