STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry must obtain its public key certificates from an appropriate certificate policy through an approved service provider.

DISA Rule

SV-251005r1028243_rule

Vulnerability Number

V-251005

Group Title

SRG-APP-000516-NDM-000344

Rule Version

MOIS-ND-000970

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry with a certificate from an approved Certificate Authority.

From MobileIron Core:
1. Log in to the MobileIron Core.
2. Navigate to "Services".
3. Select "Sentry".
4. On each configured Sentry, select "Manage Certificate".
5. Upload appropriate certificate.

From Sentry:
1. Log in to the Sentry.
2. Navigate to "Security".
3. Select "Certificate Management".
4. Select "Manage Certificate".
5. Upload appropriate certificate.

Reference "Sentry Guide for MobileIron Core" for uploading a certificate to Sentry, section "Standalone Sentry Certificate".

Check Contents

Determine if the Sentry has a public certificate from an approved Certificate Authority.

From MobileIron Core:
1. Log in to the MobileIron Core.
2. Navigate to "Services".
3. Select "Sentry".
4. On each configured Sentry, select "View Certificate".
5. Validate the Public Key is issued from an approved Certificate Authority.

From Sentry:
1. Log in to the Sentry.
2. Navigate to "Security".
3. Scroll down to "Certificate Mgmt".
4. Select "View Certificate".

If approved certificates have not been uploaded, this is a finding.

Vulnerability Number

V-251005

Documentable

False

Rule Version

MOIS-ND-000970

Severity Override Guidance

Determine if the Sentry has a public certificate from an approved Certificate Authority.

From MobileIron Core:
1. Log in to the MobileIron Core.
2. Navigate to "Services".
3. Select "Sentry".
4. On each configured Sentry, select "View Certificate".
5. Validate the Public Key is issued from an approved Certificate Authority.

From Sentry:
1. Log in to the Sentry.
2. Navigate to "Security".
3. Scroll down to "Certificate Mgmt".
4. Select "View Certificate".

If approved certificates have not been uploaded, this is a finding.

Check Content Reference

M

Target Key

5438