STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to provision digital signatures.

DISA Rule

SV-220414r961857_rule

Vulnerability Number

V-220414

Group Title

SRG-APP-000514-DB-000381

Rule Version

ML09-00-012000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure MarkLogic to use NIST FIPS validated cryptographic modules to provision digital signatures.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon.
2. Click the local cluster.
3. Enable SSL FIPS option.

Check Contents

Check MarkLogic configuration to verify use of NIST FIPS validated cryptographic modules to provision digital signatures.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon.
2. Click the local cluster.
3. If SSL FIPS enabled button is false, this is a finding.

Vulnerability Number

V-220414

Documentable

False

Rule Version

ML09-00-012000

Severity Override Guidance

Check MarkLogic configuration to verify use of NIST FIPS validated cryptographic modules to provision digital signatures.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Clusters icon.
2. Click the local cluster.
3. If SSL FIPS enabled button is false, this is a finding.

Check Content Reference

M

Target Key

4064