STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.

DISA Rule

SV-220340r960768_rule

Vulnerability Number

V-220340

Group Title

SRG-APP-000023-DB-000001

Rule Version

ML09-00-000200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If there are any accounts managed by MarkLogic, update the system documentation for justification and approval of these accounts.

Configure MarkLogic to use External Security from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon in the left tree menu.
2. Click the External Authentication icon.
3. Click the Create tab at the top of the External Authentication Summary window.
4. Complete the External Security Configuration Object for the available organization-level security provider.
5. Click the Security icon in the left tree menu.
6. Click the Users icon.
7. Select the user to fix.
8. In the User Configuration window, enter the external name for the user in the field in the External Name section.

Check Contents

If all accounts are authenticated by the organization-level authentication/access mechanism and not by the MarkLogic, this is not a finding.

If there are any accounts managed by MarkLogic, review the system documentation for justification and approval of these accounts.

If any MarkLogic-managed accounts exist that are not documented and approved, this is a finding.

Check to see if MarkLogic is configured to use External Security from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the click the Security icon in the left tree menu.
2. Click the External Security icon.
3. If no External Security Configuration Object exists, this is a finding.
4. If at least one External Security Configuration Object exists, proceed to check all existing user accounts below.
5. Click the Security icon in the left tree menu.
6. Click the Users icon.
7. Select the user to check.
8. In the User Configuration window, verify that at least one external name for the user is defined in the External Name section, if no external names are defined and justification/approval does not exists for this account, this is a finding.
9. Repeat for all users.

Vulnerability Number

V-220340

Documentable

False

Rule Version

ML09-00-000200

Severity Override Guidance

If all accounts are authenticated by the organization-level authentication/access mechanism and not by the MarkLogic, this is not a finding.

If there are any accounts managed by MarkLogic, review the system documentation for justification and approval of these accounts.

If any MarkLogic-managed accounts exist that are not documented and approved, this is a finding.

Check to see if MarkLogic is configured to use External Security from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the click the Security icon in the left tree menu.
2. Click the External Security icon.
3. If no External Security Configuration Object exists, this is a finding.
4. If at least one External Security Configuration Object exists, proceed to check all existing user accounts below.
5. Click the Security icon in the left tree menu.
6. Click the Users icon.
7. Select the user to check.
8. In the User Configuration window, verify that at least one external name for the user is defined in the External Name section, if no external names are defined and justification/approval does not exists for this account, this is a finding.
9. Repeat for all users.

Check Content Reference

M

Target Key

4064