STIGQter STIGQter: STIG Summary: VMW vRealize Automation 7.x vIDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

vIDM must utilize encryption when using LDAP for authentication.

DISA Rule

SV-100937r1_rule

Vulnerability Number

V-90287

Group Title

SRG-APP-000172-AS-000121

Rule Version

VRAU-VI-000240

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

In a browser, log in with Tenant admin privileges, and navigate to the Administration page.

Select Directories Management >> Directories.

Click on the configured Directory to review the configuration.

Check the checkbox that is labeled, "This Directory requires all connections to use SSL".

Click "Save".

Check Contents

In a browser, log in with Tenant admin privileges, and navigate to the Administration page.

Select Directories Management >> Directories.

Click on the configured Directory to review the configuration.

If the SSL checkbox is not selected, this is a finding.

Note: The checkbox is labeled, "This Directory requires all connections to use SSL".

Vulnerability Number

V-90287

Documentable

False

Rule Version

VRAU-VI-000240

Severity Override Guidance

In a browser, log in with Tenant admin privileges, and navigate to the Administration page.

Select Directories Management >> Directories.

Click on the configured Directory to review the configuration.

If the SSL checkbox is not selected, this is a finding.

Note: The checkbox is labeled, "This Directory requires all connections to use SSL".

Check Content Reference

M

Target Key

3451

Comments