STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry, for PKI-based authentication, must be configured to map validated certificates to unique user accounts.

DISA Rule

SV-250994r1028230_rule

Vulnerability Number

V-250994

Group Title

SRG-APP-000177-NDM-000263

Rule Version

MOIS-ND-000510

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Ensure that an EDIPI is mapped to the Sentry Admin user accounts.

1. Log in to the Sentry System Manager.
2. Ensure "Certificate Based Authentication" under Security Tab >> Sign-In Authentication.
3. Ensure that a Certificate Attribute Mapping is mapped to EDIPI.
4. Go to Security tab >> Local Users. Click on an active Local User and configure an EDIPI.
5. Click "Apply".
6. Repeat step for 4 for all local users.

Check Contents

Verify that an EDIPI is mapped to the Sentry Admin user accounts.

1. Log in to the Sentry System Manager.
2. Verify "Certificate Based Authentication" under Security Tab >> Sign-In Authentication.
3. Verify that a Certificate Attribute Mapping is mapped to EDIPI.
4. Go to Security tab >> Local Users. Click on an active Local User and configure an EDIPI.
5. Click "Apply".
6. Repeat step 4 for all local users.

If EDIPI is not mapped to the Sentry Admin user accounts, this is a finding.

Vulnerability Number

V-250994

Documentable

False

Rule Version

MOIS-ND-000510

Severity Override Guidance

Verify that an EDIPI is mapped to the Sentry Admin user accounts.

1. Log in to the Sentry System Manager.
2. Verify "Certificate Based Authentication" under Security Tab >> Sign-In Authentication.
3. Verify that a Certificate Attribute Mapping is mapped to EDIPI.
4. Go to Security tab >> Local Users. Click on an active Local User and configure an EDIPI.
5. Click "Apply".
6. Repeat step 4 for all local users.

If EDIPI is not mapped to the Sentry Admin user accounts, this is a finding.

Check Content Reference

M

Target Key

5438