STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes.

DISA Rule

SV-220415r961857_rule

Vulnerability Number

V-220415

Group Title

SRG-APP-000514-DB-000382

Rule Version

ML09-00-012100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

Configure MarkLogic to use a NIST FIPS validated cryptographic module for generation and verification of cryptographic hashes.

1. Click the Clusters icon.
2. Click the local cluster.
3. Enable SSL FIPS option.

Check Contents

Check MarkLogic configuration to verify use of a NIST FIPS validated cryptographic modules to generate and verify cryptographic hashes.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level-privileges.

1. Click the Clusters icon.
2. Click the local cluster.
3. If SSL FIPS enabled button is false, this is a finding.

Vulnerability Number

V-220415

Documentable

False

Rule Version

ML09-00-012100

Severity Override Guidance

Check MarkLogic configuration to verify use of a NIST FIPS validated cryptographic modules to generate and verify cryptographic hashes.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level-privileges.

1. Click the Clusters icon.
2. Click the local cluster.
3. If SSL FIPS enabled button is false, this is a finding.

Check Content Reference

M

Target Key

4064