STIGQter STIGQter: STIG Summary: Symantec ProxySG ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Apr 2020:

Symantec ProxySG must prohibit the use of cached authenticators after 300 seconds at a minimum.

DISA Rule

SV-104247r1_rule

Vulnerability Number

V-94293

Group Title

SRG-NET-000344-ALG-000098

Rule Version

SYMP-AG-000390

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set credential cache lifetimes for LDAP, RADIUS, XML, IWA (with Basic credentials), SiteMinder, and COREid authentication methods.

1. Log on to the Web Management Console.
2. Browse to Configuration >> Authentication.
3. Click each of the above authentication mechanisms and select the "General" tab (e.g., Radius General or LDAP General).
4. Set the "Credential Refresh" time to 300 at a minimum.
5. Click "Apply".

Check Contents

Verify credential cache lifetimes for LDAP, RADIUS, XML, IWA (with Basic credentials), SiteMinder, and COREid authentication methods.

1. Log on to the Web Management Console.
2. Browse to Configuration, >> Authentication.
3. Click each of the above authentication mechanisms and select the "General" tab (e.g., Radius General or LDAP General).
4. Verify that the "Credential Refresh" time is set to the organization-defined time period (a minimum of 300 seconds).

If Symantec ProxySG does not prohibit the use of cached authenticators after 300 seconds at a minimum, this is a finding.

Vulnerability Number

V-94293

Documentable

False

Rule Version

SYMP-AG-000390

Severity Override Guidance

Verify credential cache lifetimes for LDAP, RADIUS, XML, IWA (with Basic credentials), SiteMinder, and COREid authentication methods.

1. Log on to the Web Management Console.
2. Browse to Configuration, >> Authentication.
3. Click each of the above authentication mechanisms and select the "General" tab (e.g., Radius General or LDAP General).
4. Verify that the "Credential Refresh" time is set to the organization-defined time period (a minimum of 300 seconds).

If Symantec ProxySG does not prohibit the use of cached authenticators after 300 seconds at a minimum, this is a finding.

Check Content Reference

M

Target Key

3515

Comments