Red Hat Ansible Automation Controller Web Server Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
Digest of Updates ✎ 11
Comparison against the immediately-prior release (V2R3). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Content changes 11
- V-256941 Medium descriptioncheckfix The Automation Controller servers must use encrypted communication for all channels given the high impact of those services to an organization's infrastructure.
- V-256945 Medium checkfix Expansion modules must be fully reviewed, tested, and signed before they can exist on a production Automation Controller NGINX front-end web server.
- V-256947 Medium checkfix All Automation Controller NGINX web servers must not be a proxy server for any process other than the Automation Controller application.
- V-256949 Medium checkfix All Automation Controller NGINX web servers must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
- V-256952 Medium checkfix All Automation Controller NGINX web servers must be configured to use a specified IP address and port.
- V-256953 Medium checkfix Only authenticated system administrators or the designated PKI Sponsor for an Automation Controller NGINX web server must have access to any Automation Controller NGINX web server's private key.
- V-256957 Medium descriptioncheckfix The Automation Controller NGINX web server must limit the character set used for data entry.
- V-256959 Medium checkfix Debugging and trace information, within Automation Controller NGINX web server, used to diagnose the web server must be disabled.
- V-256962 Medium checkfix The Automation Controller NGINX web server must be protected from being stopped by a nonprivileged user.
- V-256964 Medium checkfix Automation Controller NGINX web servers must maintain the confidentiality of controlled information during transmission through the use of an approved TLS version.
- V-256965 Medium check The Automation Controller NGINX web servers must maintain the confidentiality and integrity of information during preparation for transmission.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- APWS-AT-000020
- Vuln IDs
-
- V-256940
- Rule IDs
-
- SV-256940r960735_rule
Checks: C-60615r903545_chk
Log in to Automation Controller as an administrator and navigate to Settings >> System >> Miscellaneous Authentication. The following parameters must be set: OAuth 2 Timeout Settings < 1800 seconds (No more than 30 minutes). The maximum number of simultaneous logged session must not be less than 0 (The default is -1) and must not match the organizationally defined maximum. Disable the built-in authentication system = ON Enable HTTP Basic Auth = Off OAuth 2 Timeout settings: "ACCESS_TOKEN_EXPIRE_SECONDS": 31536000000, "AUTHORIZATION_CODE_EXPIRE_SECONDS": 600, "REFRESH_TOKEN_EXPIRE_SECONDS": 2628000 Allow External Users to Create OAuth2 Tokens = Off Login redirect override URL = Not Configured or Blank Social Auth Organization Map = Null Social Auth Team Map = Null Social Auth User Fields = Null If any of these settings are incorrect, this is a finding.
Fix: F-60557r903541_fix
Log in to Automation Controller as an administrator and navigate to Settings >> System >> Miscellaneous Authentication. Click "Edit". Set the following parameters: OAuth 2 Timeout Settings < 1800 seconds. The maximum number of simultaneous logged session must equal 0 or the organizationally defined maximum. Disable the built-in authentication system = ON Enable HTTP Basic Auth = Off Access Token Expiration = 31536000000 Authorization Code Expiration = 600 Refresh Token Expiration = 2628000 Allow External Users to Create OAuth2 Tokens = Off Login redirect override URL = Not Configured or Blank Social Auth Organization Map = Null Social Auth Team Map = Null Social Auth User Fields = Null Click "Save".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- APWS-AT-000030
- Vuln IDs
-
- V-256941
- Rule IDs
-
- SV-256941r1262561_rule
Checks: C-60616r1262559_chk
1. Web Server Must Enforce TLS 1.2 or Higher: nginx -T 2>&1 | grep -E '^[[:space:]]*ssl_protocols' | grep -E '(TLSv1\.2|TLSv1\.3)' > /dev/null || echo "FAILED" If "FAILED" is displayed, this is a finding. 2. Web Server Must Use Host OS-Provided Cipher Policy: nginx -T 2>&1 | grep -Eq '^[[:space:]]*ssl_ciphers[[:space:]]+PROFILE=SYSTEM[[:space:]]*;[[:space:]]*$' || echo "FAILED" If "FAILED" is displayed, this is a finding. 3. External Database Connections Must Use TLS With Certificate Verification. Automation Controller may be configured to connect to PostgreSQL databases with or without TLS. The Administrator must check the contents of the file at /etc/tower/conf.d/postgres.py with root permissions to determine if pg_sslmode was configured with "verify-full" for any external databases at the time of installation. 3.1 Client-Side Execute the following command: sudo python3 -c 'exec(open("/etc/tower/conf.d/postgres.py").read()); import sys; bad=[n for n,c in DATABASES.items() if c.get("HOST") not in ("127.0.0.1","localhost","") and c.get("OPTIONS",{}).get("sslmode")!="verify-full"]; sys.exit(0 if not bad else 1)' || echo "FAILED" If "FAILED" is displayed, this is a finding. 3.2 Server-Side Confirm the database server negotiates TLS. Get DB host:port for the default connection: PGCON=$(sudo python3 -c 'exec(open("/etc/tower/conf.d/postgres.py").read()); import sys; d=DATABASES.get("default",{}); h=d.get("HOST",""); p=d.get("PORT",""); print(f"{h}:{p}" if h and p else "", end="")') Validate SSL with psql (requires psql client): test -n "$PGCON" && psql "postgresql://${PGCON}/postgres?sslmode=require" -qAt -c '\conninfo' 2>/dev/null | grep -qi 'SSL connection' || echo "FAILED" If "FAILED" is displayed, this is a finding.
Fix: F-60558r1262560_fix
Web Server TLS and Cipher Configuration As a system administrator for each Automation Controller NGINX web server: 1. Identify the active NGINX configuration files: nginx -T 2>&1 | grep '# configuration file' 2. Edit the relevant server block configuration file. 3. Ensure ssl_protocols line: ssl_protocols TLSv1.2 TLSv1.3; Ensure ssl_ciphers line: ssl_ciphers PROFILE=SYSTEM; (note the leading spaces:" ssl_ciphers PROFILE=SYSTEM;") If the directive does not exist, add it immediately after the ssl_ciphers line. 4. Save the file and apply the changes: sudo nginx -t && sudo systemctl restart nginx Database TLS Configuration 1. Edit the Ansible Automation Platform installer inventory file and set: pg_sslmode='verify-full' postgres_use_ssl=true 2. Reconfigure the controller: sudo ./setup.sh
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- APWS-AT-000040
- Vuln IDs
-
- V-256942
- Rule IDs
-
- SV-256942r960762_rule
Checks: C-60617r903519_chk
As any user, execute the following command, substituting "<controller_fqdn>" for the hostname of the Automation Controller: curl -s -w '%{redirect_url}\n' -o /dev/null http://<controller_fqdn>/api/v2/ping/ | grep '^https' >/dev/null || echo FAILED If "FAILED" is displayed, this is a finding.
Fix: F-60559r902339_fix
As a System Administrator, locate the inventory file used to install Ansible Automation Platform (usually in the installer directory). Edit this file and ensure the "nginx_disable_https" variable is absent or is set to "false". Run the setup.sh command in the installer directory to reconfigure the controller to use the new setting: sudo ./setup.sh
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- APWS-AT-000090
- Vuln IDs
-
- V-256943
- Rule IDs
-
- SV-256943r960765_rule
Checks: C-60618r902341_chk
For each Automation Controller host, determine whether the web server is logging all content related to user sessions. Log in to Automation Controller as an administrator and navigate to console Settings >> System >> Miscellaneous System. Verify the following settings: Enable Activity Stream = On Enable Activity Stream for Inventory Sync = On Organization Admins Can Manage Users and Teams = On All Users Visible to Organization Admins = On If the configuration settings are not as above, this is a finding.
Fix: F-60560r903520_fix
As a System Administrator, for each Automation Controller host, navigate to console Settings >> System >> Miscellaneous System. Click "Edit". Set the following: Enable Activity Stream = On Enable Activity Stream for Inventory Sync = On Organization Admins Can Manage Users and Teams = On All Users Visible to Organization Admins = On Click "Save".
- RMF Control
- Severity
- H
- CCI
- CCI-003992
- Version
- APWS-AT-000230
- Vuln IDs
-
- V-256944
- Rule IDs
-
- SV-256944r1016556_rule
Checks: C-60619r902344_chk
As a System Administrator, for each Automation Controller NGINX web server host, verify the integrity of the Automation Controller NGINX web server hosts files: aide --check Verify the displayed checksums against previously reserved checksums of the Advanced Intrusion Detection Environment (AIDE) database. If there are any unauthorized or unexplained changes against previous checksums, this is a finding.
Fix: F-60561r902345_fix
As a System Administrator, for each Automation Controller NGINX web server host, check for existing or install AIDE: yum install -y aide Create or update the AIDE database immediately after initial installation of each Automation Controller NGINX web server host: aide --init && mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz Accept any expected changes to the host by updating the AIDE database: aide --update The output will provide checksums for the AIDE database. Save in a protected location.
- RMF Control
- Severity
- M
- CCI
- CCI-003992
- Version
- APWS-AT-000240
- Vuln IDs
-
- V-256945
- Rule IDs
-
- SV-256945r1262564_rule
Checks: C-60620r1262562_chk
The Automation Controller does not require any NGINX dynamic expansion modules to function. As a system administrator for each Automation Controller NGINX web server host: NGINXMODPATH=$(nginx -V 2>&1 | tr ' ' '\n' | grep modules-path | sed -ne '/modules-path/{s/.*modules-path=\(.*\)/\1/;p}') nginx -T 2>&1 | grep -q load_module && echo FAILED [ $(ls -1 $NGINXMODPATH 2>/dev/null | wc -l) == 0 ] || echo FAILED If "FAILED" is displayed, this is a finding.
Fix: F-60562r1262563_fix
As a system administrator for each Automation Controller NGINX web server host: NGINXMODPATH=$(nginx -V 2>&1 | tr ' ' '\n' | grep modules-path | sed -ne '/modules-path/{s/.*modules-path=\(.*\)/\1/;p}') sudo rm -f ${NGINXMODPATH}/* Identify active config files and remove any load_module lines: nginx -T 2>&1 | grep '# configuration file' Edit each file and remove lines containing load_module. Save the file and exit the text editor. Run the following command to apply the changes: sudo systemctl restart nginx
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- APWS-AT-000250
- Vuln IDs
-
- V-256946
- Rule IDs
-
- SV-256946r960963_rule
Checks: C-60621r902350_chk
As a system administrator for each Automation Controller NGINX web server host, navigate to Settings >> Authentication. Review the configuration and verify that the appropriate authentication service is configured. If no authentication service is configured, this is a finding.
Fix: F-60563r902351_fix
As a system administrator for each Automation Controller NGINX web server host, navigate to Settings >> Authentication. Configure the appropriate authentication service.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- APWS-AT-000270
- Vuln IDs
-
- V-256947
- Rule IDs
-
- SV-256947r1262567_rule
Checks: C-60622r1262565_chk
As a system administrator (SA) for each Automation Controller NGINX web server host, ensure that the only upstream servers configured are for the Automation Controller ASGI and WSGI modules. Dump the full active NGINX configuration: nginx -T 2>&1 | grep -E 'proxy_pass|uwsgi_pass' | grep -Pqz '^\s+proxy_pass http://daphne;\n\s+uwsgi_pass uwsgi;\n$' || echo FAILED nginx -T 2>&1 | grep -Pzo 'upstream\s+daphne\s+{[^}]+}' | grep -a server | grep -v 'server unix:/var/run/tower/daphne.sock;' && echo FAILED nginx -T 2>&1 | grep -Pzo 'upstream\s+uwsgi\s+{[^}]+}' | grep -a server | grep -v 'server unix:/var/run/tower/uwsgi.sock;' && echo FAILED If "FAILED" is displayed, this is a finding.
Fix: F-60564r1262566_fix
As an SA, remove any content present and served from the static content location (/var/lib/awx/public/static) that is not acceptable per organizationally defined policy. Run the setup.sh command in the Ansible Automation Platform installer directory to reconfigure the controller to the default state, which only contains the required configuration: sudo ./setup.sh (Note: Identify the active NGINX configuration files using nginx -T 2>&1 | grep '# configuration file' to locate all included config files before editing.)
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- APWS-AT-000290
- Vuln IDs
-
- V-256948
- Rule IDs
-
- SV-256948r960963_rule
Checks: C-60623r902356_chk
As a System Administrator for each Automation Controller NGINX web server, examine NGINX users in /etc/passwd. Verify a single user "nginix" exists using the command: [ `grep -c nginx /etc/passwd` == 1 ] || echo FAILED If "FAILED" is displayed, this is a finding.
Fix: F-60565r902357_fix
As a System Administrator for each Automation Controller NGINX web server, reinstall Automation Controller if no "nginx" users exist in /etc/passwd. Review all users enumerated in /etc/passwd, and remove any that are not attributable to RHEL or Automation Controller and/or organizationally disallowed.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- APWS-AT-000310
- Vuln IDs
-
- V-256949
- Rule IDs
-
- SV-256949r1262570_rule
Checks: C-60624r1262568_chk
As a system administrator (SA) for each Automation Controller NGINX web server, check the allowed MIME types: MIME_TYPES=$(nginx -T 2>&1 | grep -m1 'include.*mime' | awk '{print $2}' | sed 's/;$//') disallowed_mime_types=('application.*\sbin' 'application.*\sexe' 'application.*\srpm' 'application.*\smsi' 'application.*\smsp' 'application.*\smsm') echo "${disallowed_mime_types[*]}" | tr ' ' '\n' > tempfile; cat $MIME_TYPES | grep -f tempfile 1>/dev/null && echo "FAILED"; rm -f tempfile If "FAILED" is displayed, this is a finding.
Fix: F-60566r1262569_fix
As an SA for each Automation Controller NGINX web server, identify the MIME types file: MIME_TYPES=$(nginx -T 2>&1 | grep -m1 'include.*mime' | awk '{print $2}' | sed 's/;$//') Remove disallowed MIME types from the file and restart NGINX.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- APWS-AT-000340
- Vuln IDs
-
- V-256950
- Rule IDs
-
- SV-256950r960963_rule
Checks: C-60625r902362_chk
As a system administrator, for each Automation Controller NGINX web server host, check the Automation Controller NGINX web server configuration for WebDAV modules: disallowed_modules=(nginx-dav-ext-module headers-more-nginx-module) ; echo "${disallowed_modules[*]}" | tr ' ' '\n' >tempfile ; nginx -V 2>&1 | grep module | tr ' ' '\n' | grep module | grep -v modules-path | grep -Ff tempfile && echo "FAILED"; rm -f tempfile If "FAILED" is displayed, this is a finding. Check the Automation Controller NGINX web server configuration for WebDAV modules for disallowed WebDAV verbs, COPY, MOVE, MKCOL, PROPFIND, PROPPATCH, LOCK, UNLOCK: NGINXCONF=`nginx -V 2>&1 | tr ' ' '\n' | sed -ne '/conf-path/{s/.*conf-path=\(.*\)/\1/;p}' ` ; grep dev_(.*)methods $NGINXCONF | grep 'COPY|MOVE|MKCO|PROPFIND|PROPPATCH|LOCK|UNLOCK' && echo 'FAILED' If "FAILED" is displayed, this is a finding.
Fix: F-60567r902363_fix
As a system administrator, for each Automation Controller nginx web server host, remove all WebDAV modules from the NGINX configuration file (nominally /etc/nginx/nginx.conf). Reload the NGINX server configurations for all NGINX processes: $ pkill -HUP nginx
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- APWS-AT-000350
- Vuln IDs
-
- V-256951
- Rule IDs
-
- SV-256951r960963_rule
Checks: C-60626r902365_chk
As a system administrator for each Automation Controller NGINX web server host, check if SELinux is enabled in enforcing mode: getenforce | grep Enforcing >/dev/null || echo FAILED If "FAILED" is displayed, this is a finding.
Fix: F-60568r902366_fix
As a system administrator for each Automation Controller NGINX web server host, place the server in SELinux enforcing mode: setenforce 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- APWS-AT-000370
- Vuln IDs
-
- V-256952
- Rule IDs
-
- SV-256952r1262573_rule
Checks: C-60627r1262571_chk
As a system administrator (SA) for each Automation Controller NGINX web server host, verify the web server is configured to use a static IP address and port: nginx -T 2>&1 | grep '^\s*listen\s*\*\|\s*listen\s*\[.*\]\|\s*listen\s*0\.0\.0\.0\|\s*listen\s*\[.*\]\|^\s*listen\s\+.*:[^[:digit:]\s]\+.*' && echo FAILED If "FAILED" is displayed, this is a finding.
Fix: F-60569r1262572_fix
As an SA, identify the active NGINX configuration files: nginx -T 2>&1 | grep '# configuration file' Edit the relevant configuration file(s) to replace any wildcard or ranged IP address references with IP addresses from the pool of allowed and/or designated addresses. Reload the NGINX server configuration: pkill -HUP nginx
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000186
- Version
- APWS-AT-000400
- Vuln IDs
-
- V-256953
- Rule IDs
-
- SV-256953r1262576_rule
Checks: C-60628r1262574_chk
As a system administrator (SA) for each Automation Controller NGINX web server host, verify the location and permissions of the private key: For containerized deployments, enter the controller web container namespace or use podman exec: TOWER_KEY=$(nginx -T 2>&1 | sed -n 's/^\s*ssl_certificate_key\s*\(.*\);/\1/p' | head -1) stat -c "%a %U %G" $TOWER_KEY Verify the key file is readable only by the service account running the NGINX process (permission mode 400 or 600, owned by the service user). If the key is world-readable or group-readable by an unauthorized group, this is a finding.
Fix: F-60570r1262575_fix
As an SA for each Automation Controller NGINX web server host, set the permissions: TOWER_KEY=$(nginx -T 2>&1 | sed -n 's/^\s*ssl_certificate_key\s*\(.*\);/\1/p' | head -1) chown <service_user>:<service_group> $TOWER_KEY chmod 600 $TOWER_KEY Note: In containerized deployments (AAP 2.6+), the service user is typically 'rhel' or the mapped UID, not root:awx. Verify the key is owned by the user running the NGINX process.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- APWS-AT-000440
- Vuln IDs
-
- V-256954
- Rule IDs
-
- SV-256954r1138072_rule
Checks: C-60629r903528_chk
As a system administrator for each Automation Controller NGINX web server host, enumerate all (nonroot) privileged users on the system: allowed_privileged_users=('root') ; echo "${allowed_privileged_users}" | tr ' ' '\n' >/tmp/allowed_privileged_users ; getent passwd | cut -f1 -d ':' | sudo xargs -L1 sudo -l -U | grep -v 'not allowed' | tail -n +3 | sed -n '/^User/s/User\s*\(\w*\).*/\1/p' | grep -v -f /tmp/allowed_privileged_users 1>/dev/null && echo "FAILED" ; rm -f /tmp/allowed_privileged_users If "FAILED" is displayed, this is a finding.
Fix: F-60571r902375_fix
As a System Administrator for each Automation Controller NGINX web server host, enumerate all (nonroot) privileged users on the system: getent passwd | cut -f1 -d ':' | sudo xargs -L1 sudo -l -U | grep -v 'not allowed' | tail -n +3 | sed -n '/^User/s/User\s*\(\w*\).*/\1/p' | grep -v root For each user shown, perform one of the following actions: - Remove the indicated user from the system; - Remove the indicated user from any privileged groups (wheel); - Remove login access for the user; - Verify via organizationally defined procedures the indicated user is an authorized administrative account.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001664
- Version
- APWS-AT-000480
- Vuln IDs
-
- V-256955
- Rule IDs
-
- SV-256955r1043180_rule
Checks: C-60630r902377_chk
The Automation Controller application configures cookie properties appropriately by default. Any local modifications to cookie-related settings must be located and removed. As a System Administrator for each Automation Controller NGINX web server host, search for modified cookie variables in the Automation Controller configuration: sudo grep -r -E '(CSRF|SESSION)_COOKIE_(HTTPONLY|SECURE|SAMESITE)' /etc/tower/settings.py /etc/tower/conf.d/ If any output is shown, this is a finding.
Fix: F-60572r902378_fix
As a System Administrator for each Automation Controller NGINX web server host, remove any local variable changes related to cookie properties: sudo grep -r -E '(CSRF|SESSION)_COOKIE_(HTTPONLY|SECURE|SAMESITE)' /etc/tower/settings.py /etc/tower/conf.d/ For each result, edit the relevant file. For example, if a variable is found in /etc/tower/settings.py, edit the file with the following command: sudo -e /etc/tower.settings.py Remove any line where the following variables are defined: SESSION_COOKIE_HTTPONLY SESSION_COOKIE_SECURE SESSION_COOKIE_SAMESITE CSRF_COOKIE_HTTPONLY CSRF_COOKIE_SECURE CSRF_COOKIE_SAMESITE Execute the following command to restart the Automation Controller service: sudo automation-controller-service restart
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- APWS-AT-000590
- Vuln IDs
-
- V-256956
- Rule IDs
-
- SV-256956r961131_rule
Checks: C-60631r903529_chk
Automation Controller serves static public content from the directory /var/lib/awx/public. As a System Administrator for each Automation Controller NGINX web server host, verify that a separate file system/partition has been created for /var/lib/awx/public: [[ $(sudo awk '$0~"/var/lib/awx/public" {print $2}' /etc/fstab) == "/var/lib/awx/public" ]] || echo "FAILED" If "FAILED" is displayed, this is a finding.
Fix: F-60573r902381_fix
As a System Administrator for each Automation Controller NGINX web server host, migrate the "/var/lib/awx/public" path onto a separate file system. No automated fix is available for this action.
- RMF Control
- SI-10
- Severity
- M
- CCI
- CCI-001310
- Version
- APWS-AT-000610
- Vuln IDs
-
- V-256957
- Rule IDs
-
- SV-256957r1262579_rule
Checks: C-60632r1262577_chk
As a system administrator (SA) for each Automation Controller NGINX web server, verify the NGINX configuration includes a default charset directive: nginx -T 2>&1 | grep -E '^\s*charset\s' || echo "FAILED" If "FAILED" is displayed, this is a finding. (Note: On a default AAP 2.6 installation, this directive is not present. The fix below must be applied.)
Fix: F-60574r1262578_fix
As an SA for each Automation Controller NGINX web server, add the charset directive to the NGINX configuration. Identify the active configuration files: nginx -T 2>&1 | grep '# configuration file' Edit the server block (within the http {} context) and add: charset utf-8; Validate and reload: nginx -t && systemctl reload nginx For containerized deployments, apply the directive within the container's NGINX configuration and restart the container service.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- APWS-AT-000620
- Vuln IDs
-
- V-256958
- Rule IDs
-
- SV-256958r961167_rule
Checks: C-60633r903555_chk
For each Automation Controller NGINX web server, a system administrator must view to see whether autoindex is turned on or off (autoindex on/autoindex off): NGINXCONF=`nginx -V 2>&1 | tr ' ' '\n' | sed -ne '/conf-path/{s/.*conf-path=\(.*\)/\1/;p}' ` ; grep -E 'autoindex\s+on' $NGINXCONF && echo "FAILED" If "FAILED" is displayed, this is a finding.
Fix: F-60575r902387_fix
As a System Administrator for each Automation Controller nginx web server host, remove any configuration that turns the autoindexing on: NGINXCONF=`nginx -V 2>&1 | tr ' ' '\n' | sed -ne '/conf-path/{s/.*conf-path=\(.*\)/\1/;p}' ` ; sed -Ei -e '/autoindex\s+on/d;' $NGINXCONF To apply these changes to the running service immediately, restart the NGINX service with the following command: sudo systemctl restart nginx
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- APWS-AT-000640
- Vuln IDs
-
- V-256959
- Rule IDs
-
- SV-256959r1262582_rule
Checks: C-60634r1262580_chk
For each Automation Controller NGINX web server, a system administrator must check to determine if any error or debug information is being logged to a persistent file (not stdout/stderr): nginx -T 2>&1 | grep '^\s*error_log' | grep -v '/dev/stdout\|/dev/stderr\|/dev/null' && echo FAILED If "FAILED" is displayed, this is a finding. Note: In containerized deployments (AAP 2.6+), error_log /dev/stdout error; is the expected configuration - container runtimes collect stdout via journald or the container logging driver. This is NOT a finding. Only error_log directives pointing to persistent files on disk constitute a finding.
Fix: F-60576r1262581_fix
For each Automation Controller NGINX web server, identify the active configuration files: nginx -T 2>&1 | grep '# configuration file' If error_log points to a file on disk, either remove the directive or redirect to /dev/stdout: error_log /dev/stdout error; Cause NGINX to reload its configuration file: pkill -HUP nginx
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- APWS-AT-000700
- Vuln IDs
-
- V-256960
- Rule IDs
-
- SV-256960r961353_rule
Checks: C-60635r903547_chk
As a system administrator, for each Automation Controller NGINX web server host, inspect the current permissions and owner of Tower's web server configuration directory: stat -c "%a %U %G" /etc/nginx | grep -q "755 root root" || echo "FAILED" stat -c "%a %U %G" /etc/nginx/conf.d | grep -q "755 root root" || echo "FAILED" stat -c "%a %U %G" /etc/nginx/nginx.conf | grep -q "644 root root" || echo "FAILED" If "FAILED" is displayed, this is a finding. Inspect the current permissions and owner of Automation Controller web server program configuration files: stat -c "%a %U %G" /usr/lib/systemd/system/nginx.service | grep -q "644 root root" || echo "FAILED" If "FAILED" is displayed, this is a finding. Inspect the current permissions and owner of Automation Controller application content directory: stat -c "%a %U %G" /var/lib/awx/public/static | grep -q "755 root awx" || echo "FAILED" If "FAILED" is displayed, this is a finding. Inspect the current permissions and owner of Automation Controller web server log directory: stat -c "%a %U %G" /var/log/nginx| grep -q "770 nginx root" || echo "FAILED" If "FAILED" is displayed, this is a finding.
Fix: F-60577r902393_fix
As a system administrator, for each Automation Controller NGINX web server host, set the permissions and owner of Automation Controller web server program configuration directory: sudo chown -R root:root /etc/nginx/ sudo chmod 755 /etc/nginx /etc/nginx sudo chmod 755 /etc/nginx /etc/nginx/conf.d sudo chmod 644 /etc/nginx/nginx.conf As a system administrator, for each Automation Controller NGINX web server program configuration files. sudo chown root:root /usr/lib/systemd/system/nginx.service sudo chmod 644 /usr/lib/systemd/system/nginx.service Set the permissions and owner of Automation Controller application content directory: sudo chmod 755 /var/lib/awx/public/static sudo chown root:awx /var/lib/awx/public/static
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- APWS-AT-000780
- Vuln IDs
-
- V-256961
- Rule IDs
-
- SV-256961r961461_rule
Checks: C-60636r902395_chk
As a System Administrator for each Automation Controller NGINX web server host, check that the file permissions for the web server components require privileged access: $ [ `find /etc/nginx -type f -not -perm 644 | wc -l` -gt 0 ] && echo "FAILED" If "FAILED" is displayed, this is a finding.
Fix: F-60578r902396_fix
As a System Administrator for each Automation Controller NGINX web server host, modify the file permissions for the web server components require privileged access: chmod -R 644 /etc/nginx && chown -R nginx /etc/nginx
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- APWS-AT-000830
- Vuln IDs
-
- V-256962
- Rule IDs
-
- SV-256962r1262585_rule
Checks: C-60637r1262583_chk
As a system administrator (SA) for each Automation Controller NGINX web server host, verify required service definition is protected from unprivileged users: stat -c "%a %U %G" /usr/lib/systemd/system/automation-controller.service | grep -q "644 root root" || echo "FAILED" stat -c "%a %U %G" /usr/lib/systemd/system/supervisord.service | grep -q "644 root root" || echo "FAILED" stat -c "%a %U %G" /usr/lib/systemd/system/nginx.service | grep -q "644 root root" || echo "FAILED" If "FAILED" is displayed, this is a finding. Verify the required services are enabled: systemctl is-enabled automation-controller.service >/dev/null || echo FAILED systemctl is-enabled supervisord.service >/dev/null || echo FAILED systemctl is-enabled nginx.service >/dev/null || echo FAILED If "FAILED" is displayed, this is a finding. Verify application services are correctly managed by supervisord. Verify protection of and capture supervisord configuration. stat -c "%a %U %G" /etc/supervisord.d/*.ini | grep -q "644 root root" || echo "FAILED" cat /etc/supervisord.d/*.ini | sed -n -E "/^\[.*\]/{s/\[(.*)\]/\1/;h;n;};/^[a-zA-Z]/{s/#.*//;G;s/([^ ]*) *= *(.*)\n(.*)/\3_\1='\2'/;p;}" > /tmp/supervisord.parsed.conf Verify specific start and restart properties for application services: application_services=(program:awx-dispatcher_autostart program:awx-dispatcher_autorestart program:awx-uwsgi_autostart program:awx-uwsgi_autorestart program:awx-daphne_autostart program:awx-daphne_autorestart program:awx-rsyslogd_autostart program:awx-rsyslogd_autorestart) for SUPERVISOR_CHECK in ${application_services[@]}; do grep $SUPERVISOR_CHECK /tmp/supervisord.parsed.conf | grep -q true || echo "FAILED" ; done rm /tmp/supervisord.parsed.conf If "FAILED" is displayed, this is a finding.
Fix: F-60579r1262584_fix
As an SA for each Automation Controller NGINX web server host, set the permissions correctly on the nginx service file: sudo chown root:root /usr/lib/systemd/system/nginx.service sudo chmod 644 /usr/lib/systemd/system/nginx.service Reset the Ansible Automation Platform configuration to the defaults, which meet the requirements for the supervisord and automation-controller services. Locate the inventory file used to install Ansible Automation Platform (usually in the installer directory). Run the setup.sh command in the installer directory to reconfigure the controller to use the new setting: sudo ./setup.sh
- RMF Control
- SC-8
- Severity
- H
- CCI
- CCI-002418
- Version
- APWS-AT-000850
- Vuln IDs
-
- V-256963
- Rule IDs
-
- SV-256963r1016551_rule
Checks: C-60638r1016549_chk
As a System Administrator for each Automation Controller NGINX web server host, enumerate all available server connections: NGINXCONF=$(nginx -V 2>&1 | tr ' ' '\n' | sed -ne '/conf-path/{s/.*conf-path=\(.*\)/\1/;p}') grep '\s*listen' NGINXCONF | grep -v ssl Ensure each available server connection that does not use SSL upgrades this connection to use SSL via an allowed method: - is redirected to an SSL server connection, e.g., "return 301 https://$host:443$request_uri"; - is rewritten to an SSL server URL, e.g., "rewrite ^ https://$host$request_uri? permanent;"; - is dropped silently; - or used other organizationally approved connection handling. Examine the NGINX configuration, for example: vi $NGINXCONF If any available server connection is not handled or upgraded to SSL via an organizationally approved method, this is a finding. vi $NGINXCONF If any available server connection is not handled or upgraded to SSL via an organizationally approved method, this is a finding.
Fix: F-60580r1016550_fix
As a System Administrator for each Automation Controller NGINX web server host, for each available server connection that is not handled or upgraded to SSL via an organizationally approved method, perform one of the following actions: Remove the available server connections. OR Upgrade the connection via redirect to an SSL server connection. OR Rewrite the connection URL to an HTTPS server connection. OR Other organizationally defined handling method. Reload the NGINX server configuration by executing the following: pkill -HUP nginx (Alternatively, reinstall Automation Controller for each web server host.)
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- APWS-AT-000900
- Vuln IDs
-
- V-256964
- Rule IDs
-
- SV-256964r1262588_rule
Checks: C-60639r1262586_chk
As a system administrator (SA), for each Automation Controller NGINX web server, validate the TLS version configuration: nginx -T 2>&1 | grep ssl_protocols | grep -E 'ssl_protocols\s+TLSv1.2;' || echo "FAILED" If "FAILED" is displayed, this is a finding.
Fix: F-60581r1262587_fix
As an SA, identify the active NGINX configuration files: nginx -T 2>&1 | grep '# configuration file' Edit the relevant configuration file. Replace or add the ssl_protocols line: ssl_protocols TLSv1.2; Save the file and restart NGINX: sudo systemctl restart nginx
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002420
- Version
- APWS-AT-000920
- Vuln IDs
-
- V-256965
- Rule IDs
-
- SV-256965r1262590_rule
Checks: C-60640r1262589_chk
As a system administrator (SA) for each Automation Controller NGINX web server host, verify the NGINX web server configuration file in use is located at "/etc/nginx/nginx.conf": NGINXCONF=`nginx -V 2>&1 | tr ' ' '\n' | sed -ne '/conf-path/{s/.*conf-path=\(.*\)/\1/;p}' ` If the file does not exist, this is a finding. Verify the use of only dynamic modules witch are allowed by organizational policy: allowed_modules=(ssl_module http_v2_module http_realip_module http_addition_module http_xslt_module=dynamic http_image_filter_module=dynamic http_sub_module http_dav_module http_mp4_module http_gunzip_module http_gzip_static_module http_random_index_module http_secure_link_module http_degradation_module http_slice_module http_stub_status_module http_perl_module=dynamic http_auth_request_module mail_ssl_module stream_ssl_module stream_ssl_preread_module http_flv_module stream_realip_module) echo "${allowed_modules[*]}" | tr ' ' '\n' > /tmp/allowed_modules nginx -V 2>&1 | grep module | tr ' ' '\n' | grep module | grep -v modules-path | sed 's/--with-//g' | grep -v -Ff /tmp/allowed_modules && echo "FAILED" Verify the use of only runtime modules which are allowed by organizational policy: nginx -T 2>&1 | grep load_module | sed -n 's/^\s*load_module\s*\(.*\)/\1/p' | grep -v -Ff /tmp/allowed_modules && echo "FAILED"; rm -f /tmp/allowed_modules If the output shows "FAILED", this is a finding.
Fix: F-60582r1155092_fix
As an SA for each Automation Controller NGINX web server host, verify the NGINX web server configuration file in use is located at "/etc/nginx/nginx.conf": NGINXCONF=`nginx -V 2>&1 | tr ' ' '\n' | sed -ne '/conf-path/{s/.*conf-path=\(.*\)/\1/;p}' ` ; Verify the location of the NGINX modules libraries: pushd `nginx -V 2>&1 | grep module | tr ' ' '\n' | grep module | sed -n 's/.*modules-path.*=\s*\(.*\)/\1/p'` Remove all modules that violate organizationally defined policy. Examine runtime loaded modules: grep load_module nginx.conf.test | sed -n 's/^\s*load_module\s*\(.*\)/\1/p' Remove all modules that violate organizationally defined policy. Examine the remainder of the modules: nginx -V 2>&1 | grep module | tr ' ' '\n' | grep module | grep -v modules-path These modules are compiled into the core NGINX binaries are cannot be removed. Use of any these modules that violate organizationally defined policy must be mitigated. To apply these changes to the running service immediately, restart the NGINX service with the following command: sudo systemctl restart nginx Alternatively, reinstall Automation Controller for each web server host.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- APWS-AT-000940
- Vuln IDs
-
- V-256966
- Rule IDs
-
- SV-256966r1138080_rule
Checks: C-60641r902410_chk
As a System Administrator for each Automation Controller NGINX web server host, verify the system is configured to receive updates from an organizationally defined source for authoritative system updates: yum -v repolist If each URL is not valid and consistent with organizationally defined requirements, this is a finding. If each repository is not enabled in accordance with organizationally defined requirements, this is a finding. If the system is not configured to automatically receive and apply system updates from this source at least every 30 days, or manually receive and apply updates at least every 30 days, this is a finding.
Fix: F-60583r903536_fix
As a system administrator, for each Automation Controller NGINX web server host, perform the following: 1. Either configure update repositories in accordance with organizationally defined requirements or subscribe to Red Hat update repositories for the underlying operating system. 2. Execute an update from these repositories: $ yum update -y 3. Perform one of the following: 3.1. Schedule an update to occur every 30 days, or in accordance with organizationally defined policy: $ yum install -y dnf-automatic && sed -i '/apply_updates/s/no/yes/' /etc/dnf/automatic.conf && sed -i '/OnCalendar/s/^OnCalendar\s*=.*/OnCalendar=*-1-* 6:00/' /usr/lib/systemd/system/dnf-automatic.timer && systemctl enable --now dnf-automatic.timer 3.2. Schedule manual updates to occur at least every 30 days, or in accordance with organizationally defined policy. 4. Restart the Automation Controller NGINX web server host.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- APWS-AT-000950
- Vuln IDs
-
- V-256967
- Rule IDs
-
- SV-256967r961863_rule
Checks: C-60642r903537_chk
As a System Administrator for each Automation Controller NGINX web server host, verify the NGINX account is configured to disallow interactive login" grep '^nginx.*\(/sbin/nologin$\|/bin/false$\)' /etc/passwd If "FAILED" is displayed, this is a finding.
Fix: F-60584r902414_fix
As a System Administrator for each Automation Controller NGINX web server host, change the NGINX account to disallow interactive login: $ usermod -s /sbin/nologin nginx