SV-220363r960969_rule
V-220363
SRG-APP-000148-DB-000103
ML09-00-003500
CAT II
10
Configure MarkLogic settings to uniquely identify and authenticate all organizational users who log on/connect to the system.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select each of the App Servers.
5. Inspect the selected authentication method. If "application-level" is selected and a user other than "nobody" (or equivalent) is set as the default user, then change the default user to "nobody".
Review DBMS settings to determine whether organizational users are uniquely identified and authenticated when logging on/connecting to the system.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select each of the App Servers.
5. Inspect the selected authentication method. If "application-level" is selected and a user other than "nobody" (or equivalent) is set as the default user, this is a finding.
V-220363
False
ML09-00-003500
Review DBMS settings to determine whether organizational users are uniquely identified and authenticated when logging on/connecting to the system.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select each of the App Servers.
5. Inspect the selected authentication method. If "application-level" is selected and a user other than "nobody" (or equivalent) is set as the default user, this is a finding.
M
4064