ONTAP must be configured to use an authentication server to provide multifactor authentication.
DISA Rule
SV-246940r1211037_rule
Vulnerability Number
V-246940
Group Title
SRG-APP-000516-NDM-000336
Rule Version
NAOT-CM-000002
Severity
CAT I
CCI(s)
- CCI-000370 - Manage configuration settings for organization-defined system components using organization-defined automated mechanisms.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000166 - Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
- CCI-000185 - For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
Weight
10
Fix Recommendation
Configure ONTAP to use Active Directory to authenticate users and prohibit the use of cached authenticators with "security login create -user-or-group-name <user or group name> -authentication-method domain -application ssh".
Note: The authentication method "domain" is one example. Other authentication methods such as "publickey" and "saml" are also acceptable.
Check Contents
Use "security login show -authentication-method domain" to see users configured to authenticate with Active Directory.
If ONTAP is not configured to use an authentication server, this is a finding.
Note: The authentication method "domain" is one example. Other authentication methods such as "publickey" and "saml" are also acceptable.
Vulnerability Number
V-246940
Documentable
False
Rule Version
NAOT-CM-000002
Severity Override Guidance
Use "security login show -authentication-method domain" to see users configured to authenticate with Active Directory.
If ONTAP is not configured to use an authentication server, this is a finding.
Note: The authentication method "domain" is one example. Other authentication methods such as "publickey" and "saml" are also acceptable.
Check Content Reference
M
Target Key
5415