1. Home
  2. Security Hardening
  3. DISA STIG VMware vSphere 6.7 STS Tomcat V1R1
  4. VCST-67-000008 – The Security Token Service application files must be verified for their integrity.

VCST-67-000008 – The Security Token Service application files must be verified for their integrity.

Details

Verifying that the Security Token Service application code is unchanged from its shipping state is essential for file validation and non-repudiation of the Security Token Service. There is no reason the MD5 hash of the rpm original files should be changed after installation, excluding configuration files.

Satisfies: SRG-APP-000131-WSR-000051, SRG-APP-000357-WSR-000150

Solution

Reinstall the VCSA or roll back to a snapshot.

Modifying the Security Token Service installation files manually is not supported by VMware.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability, Configuration Management.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles