STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations and protect classified information in accordance with the requirements of the data owner.

DISA Rule

SV-220368r961050_rule

Vulnerability Number

V-220368

Group Title

SRG-APP-000179-DB-000114

Rule Version

ML09-00-004300

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Ensure SSL FIPS has been enabled in MarkLogic server.

Perform the fix operation from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon.
2. Click the Configure tab.
3. Set the value for "ssl fips enabled" to "true" and click OK.

Check Contents

Review MarkLogic configuration to determine whether SSL FIPS has been enabled.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon.
2. In the Summary tab, if the value for "ssl fips enabled" is "false", this is a finding.

Vulnerability Number

V-220368

Documentable

False

Rule Version

ML09-00-004300

Severity Override Guidance

Review MarkLogic configuration to determine whether SSL FIPS has been enabled.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon.
2. In the Summary tab, if the value for "ssl fips enabled" is "false", this is a finding.

Check Content Reference

M

Target Key

4064