1. Home
  2. Security Hardening
  3. DISA STIG VMware vSphere 6.7 STS Tomcat V1R1
  4. VCST-67-000010 – The Security Token Service must not be configured with unused realms.

VCST-67-000010 – The Security Token Service must not be configured with unused realms.

Details

The Security Token Service performs user authentication at the application level and not through Tomcat. To eliminate unnecessary features and ensure that the Security Token Service remains in its shipping state, the lack of a ‘UserDatabaseRealm’ configuration must be confirmed.

Solution

Navigate to and open /usr/lib/vmware-sso/vmware-sts/conf/server.xml.

Remove the node returned in the check.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles