Details
Use the transport-guarantee attribute to ensure SSL protection when accessing the manager application.
Rationale:
By default when accessing the manager application, login information is sent over the wire in plain text. By setting the transport-guarantee within web.xml, SSL is enforced.
Note: This requires SSL to be configured.
Solution
Set
Default Value:
By default this configuration is not present.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Unix.