STIGQter STIGQter: STIG Summary: Infoblox 8.x DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Jan 2021:

Infoblox systems must enforce current DoD password restrictions.

DISA Rule

SV-233883r621666_rule

Vulnerability Number

V-233883

Group Title

SRG-APP-000516-DNS-000500

Rule Version

IDNS-8X-400025

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

1. Navigate to Grid >> Grid Manager >> Grid Properties, or System >> System Manager >> System Properties if using a stand-alone configuration.
2. Select the "Password" tab.
3. Configure the system with appropriate values for password length, complexity, and expiration requirements.

Check Contents

1. Navigate to Administration >> Administrators >> Authentication Policy.
2. If the only authentication type under "Authenticate users in this order" is "Local User Database", perform the following additional validation:
3. Navigate to Grid >> Grid Manager >> Grid Properties, or System >> System Manager >> System Properties if using a stand-alone configuration.
4. Select the "Password" tab.
5. Verify the settings are configured in accordance with current DoD Policy.

If the Infoblox system is configured to use a remote authentication system (Active Directory, RADIUS, TACACS+, or LDAP) that enforces password policy, or the password settings meet current guidance, this is not a finding.

Vulnerability Number

V-233883

Documentable

False

Rule Version

IDNS-8X-400025

Severity Override Guidance

1. Navigate to Administration >> Administrators >> Authentication Policy.
2. If the only authentication type under "Authenticate users in this order" is "Local User Database", perform the following additional validation:
3. Navigate to Grid >> Grid Manager >> Grid Properties, or System >> System Manager >> System Properties if using a stand-alone configuration.
4. Select the "Password" tab.
5. Verify the settings are configured in accordance with current DoD Policy.

If the Infoblox system is configured to use a remote authentication system (Active Directory, RADIUS, TACACS+, or LDAP) that enforces password policy, or the password settings meet current guidance, this is not a finding.

Check Content Reference

M

Target Key

5251

Comments