STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

If passwords are used for authentication, the MarkLogic Server must transmit only encrypted representations of passwords.

DISA Rule

SV-220365r961029_rule

Vulnerability Number

V-220365

Group Title

SRG-APP-000172-DB-000075

Rule Version

ML09-00-003800

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

If the MarkLogic application server in question is configured with "digest" or "digest-basic" authentication or is configured with "Application Level" authentication and is not SSL enabled, implement the corrective action outlined below.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select each of the App Servers.
5. Inspect the selected authentication method, if "basic" or "digest-basic" is selected, change the authentication method to something other than those two.

If Application Level is selected, ensure the application server is configured for SSL.

Check Contents

Review MarkLogic configuration settings for encrypting passwords in transit across the network.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select each of the App Servers.
5. Inspect the selected authentication method, if "basic" or "digest-basic" is selected, this is a finding.

If Application Level is selected and the application server is not configured for SSL, this is a finding

Vulnerability Number

V-220365

Documentable

False

Rule Version

ML09-00-003800

Severity Override Guidance

Review MarkLogic configuration settings for encrypting passwords in transit across the network.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select each of the App Servers.
5. Inspect the selected authentication method, if "basic" or "digest-basic" is selected, this is a finding.

If Application Level is selected and the application server is not configured for SSL, this is a finding

Check Content Reference

M

Target Key

4064