Check: TCAT-AS-000280
Apache Tomcat 9 STIG:
TCAT-AS-000280
(in version v1 r0.1)
Title
AccessLogValve must be configured for each application context. (Cat II impact)
Discussion
Tomcat has the ability to host multiple contexts (applications) on one physical server by using the element. This allows the admin to specify audit log settings on a per application basis. false
Check Content
As an elevated user on the Tomcat server: Edit the $CATALINA_HOME\conf\server.xml file. Review for all <Host> elements. EXAMPLE: <Host name="localhost" appBase="webapps" unpackWARs="true" autoDeploy="false"> ... <Valve className="org.apache.catalina.valves.AccessLogValve" directory="logs" prefix="localhost_access_log" suffix=".txt" pattern="%h %l %t %u "%r" %s %b" /> ... </Host> If a <Valve className="org.apache.catalina.valves.AccessLogValve" .../> element is not defined for each <Host> element, this is a finding.
Fix Text
As a privileged user on the Tomcat server: Edit the $CATALINA_HOME\conf\server.xml file. Create a <Valve> element that is nested within the <Host> element. Specify an AccessLogValve setting in the Valve element with the following pattern statement. EXAMPLE: <Host name="localhost" appBase="webapps" unpackWARs="true" autoDeploy="false"> ... <Valve className="org.apache.catalina.valves.AccessLogValve" directory="logs" prefix="localhost_access_log" suffix=".txt" pattern="%h %l %t %u "%r" %s %b" /> ... </Host> Restart the Tomcat server: sudo systemctl restart tomcat sudo systemctl daemon-reload
Additional Identifiers
Rule ID: TCAT-AS-000280_rule
Vulnerability ID: TCAT-AS-000280
Group Title: SRG-APP-000098-AS-000061
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000133 |
The information system generates audit records containing information that establishes the source of the event. |
Controls
Number | Title |
---|---|
AU-3 |
Content Of Audit Records |