STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must enforce authorized access to all PKI private keys stored/utilized by the DBMS.

DISA Rule

SV-220367r961041_rule

Vulnerability Number

V-220367

Group Title

SRG-APP-000176-DB-000068

Rule Version

ML09-00-004000

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Ensure SSL FIPS has been enabled in MarkLogic server.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon on the left tree menu.
2. Select the local cluster. Click the Configure tab.
3. Set the "ssl fips enabled" setting to true and click "ok".

Check Contents

Review MarkLogic configuration to determine whether SSL FIPS has been enabled.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon on the left tree menu.
2. Select the local cluster. Click the Configure tab and verify "ssl fips enabled" is set to true. If not, this is a finding.

Vulnerability Number

V-220367

Documentable

False

Rule Version

ML09-00-004000

Severity Override Guidance

Review MarkLogic configuration to determine whether SSL FIPS has been enabled.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon on the left tree menu.
2. Select the local cluster. Click the Configure tab and verify "ssl fips enabled" is set to true. If not, this is a finding.

Check Content Reference

M

Target Key

4064