STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry must be configured to implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.

DISA Rule

SV-251001r1028239_rule

Vulnerability Number

V-251001

Group Title

SRG-APP-000412-NDM-000331

Rule Version

MOIS-ND-000810

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure Sentry to use FIPS 140-2 approved algorithms to protect the confidentiality of remote maintenance sessions:

1. SSH to the Sentry.
2. At the prompt, enter "enable" mode with the secret credentials.
3. Type Configure command.
4. Type FIPS.
5. Once reloaded, SSH to the Sentry.
6. Run the "show FIPS" command.

FIPS 140 mode is enabled.

Check Contents

On Sentry console, do the following to verify FIPS mode is activated to protect the confidentiality of remote maintenance sessions:

1. SSH to the Sentry.
2. Run the "show FIPS" command.
3. Verify FIPS 140 mode is not disabled.

If FIPS 140-2 mode is disabled, this is a finding.

Vulnerability Number

V-251001

Documentable

False

Rule Version

MOIS-ND-000810

Severity Override Guidance

On Sentry console, do the following to verify FIPS mode is activated to protect the confidentiality of remote maintenance sessions:

1. SSH to the Sentry.
2. Run the "show FIPS" command.
3. Verify FIPS 140 mode is not disabled.

If FIPS 140-2 mode is disabled, this is a finding.

Check Content Reference

M

Target Key

5438