STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must only accept end-entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions.

DISA Rule

SV-220386r961596_rule

Vulnerability Number

V-220386

Group Title

SRG-APP-000427-DB-000385

Rule Version

ML09-00-008400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure MarkLogic to accept only DoD and DoD-approved PKI end-entity certificates by revoking trust in any certificates not issued by a DoD-approved certificate authority.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Certificate Authorities icon.
3. Remove all PKI end-entity certificates not approved by DoD.

Check Contents

Review MarkLogic settings to determine whether the server will accept non-DoD approved PKI end-entity certificates, this is a finding.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Certificate Authorities icon.
3. If there are any PKI end-entity certificates that are not DoD approved, this is a finding.

Vulnerability Number

V-220386

Documentable

False

Rule Version

ML09-00-008400

Severity Override Guidance

Review MarkLogic settings to determine whether the server will accept non-DoD approved PKI end-entity certificates, this is a finding.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Certificate Authorities icon.
3. If there are any PKI end-entity certificates that are not DoD approved, this is a finding.

Check Content Reference

M

Target Key

4064