STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must shut down by default upon audit failure, to include the unavailability of space for more audit log records; or must be configurable to shut down upon audit failure.

DISA Rule

SV-220348r960915_rule

Vulnerability Number

V-220348

Group Title

SRG-APP-000109-DB-000049

Rule Version

ML09-00-001600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the database to go offline, rolling back all in-flight transactions, in the case of an auditing failure due to insufficient disk space.

Perform the fix from the MarkLogic Admin Interface with a user that holds administrative-level privileges:

1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. On the Configuration tab set the value of "failover enabled" to "false".
4. Click OK to save the configuration.

Check Contents

If the application owner has determined the need for system availability outweighs the need for a complete audit trail, this is not applicable.

If the system is configured for High Availability (HA), and the application owner has determined the need for a complete audit trail outweighs the need for system availability, this is a finding.

The following are the minimum configuration requirements for HA:
- Failover enabled = True for the Group
- Security database forests are configured with replica forests
- Databases associated with the users application are configured with replica forests

If HA is a requirement for Administrative functions:
- App Services database forests are configured with replica forests
- Modules database forests are configured with replica forests
- Documents database forests are configured with replica forests
- Triggers database forests are configured with replica forests

Perform the check for HA from the MarkLogic Admin Interface with a user that holds administrative-level privileges:

1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. On the Configuration tab, check the value of "failover enabled".
True = HA can be enabled
False = HA cannot be enabled
4. Click the Databases icon in the left tree menu.
5. Click the Security Database.
6. Click the Status Tab.
7. Review the Forest section:
a. Count the number of forests with a state of "open".
b. Count the number of forests with a state of "[sync|async|wait] replicating".
c. The number of replicating forests should be greater than or equal to the number of open forests.
8. Repeat steps 4-7 for the user application databases (data/content, modules, triggers, etc.).
9. Repeat steps 4-7 for the following databases if HA is required for Administrative functions:
- App Services
- Modules
- Documents
- Triggers

Vulnerability Number

V-220348

Documentable

False

Rule Version

ML09-00-001600

Severity Override Guidance

If the application owner has determined the need for system availability outweighs the need for a complete audit trail, this is not applicable.

If the system is configured for High Availability (HA), and the application owner has determined the need for a complete audit trail outweighs the need for system availability, this is a finding.

The following are the minimum configuration requirements for HA:
- Failover enabled = True for the Group
- Security database forests are configured with replica forests
- Databases associated with the users application are configured with replica forests

If HA is a requirement for Administrative functions:
- App Services database forests are configured with replica forests
- Modules database forests are configured with replica forests
- Documents database forests are configured with replica forests
- Triggers database forests are configured with replica forests

Perform the check for HA from the MarkLogic Admin Interface with a user that holds administrative-level privileges:

1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. On the Configuration tab, check the value of "failover enabled".
True = HA can be enabled
False = HA cannot be enabled
4. Click the Databases icon in the left tree menu.
5. Click the Security Database.
6. Click the Status Tab.
7. Review the Forest section:
a. Count the number of forests with a state of "open".
b. Count the number of forests with a state of "[sync|async|wait] replicating".
c. The number of replicating forests should be greater than or equal to the number of open forests.
8. Repeat steps 4-7 for the user application databases (data/content, modules, triggers, etc.).
9. Repeat steps 4-7 for the following databases if HA is required for Administrative functions:
- App Services
- Modules
- Documents
- Triggers

Check Content Reference

M

Target Key

4064