STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x ALG Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry that provides intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52.

DISA Rule

SV-251013r1028178_rule

Vulnerability Number

V-251013

Group Title

SRG-NET-000062-ALG-000150

Rule Version

MOIS-AL-000180

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry to comply with applicable required TLS settings in NIST PUB SP 800-52.

1. Log in to Sentry.
2. Go to Settings >> Services >> Sentry.
3. For each of the following configurations, follow the step 4 procedure:
a. Incoming SSL configuration
b. Outgoing SSL configuration
c. UEM SSL configuration
d. Access SSL configuration
4. Select only TLS 1.2 and remove others if selected.
5. Click "Apply".

Check Contents

Verify the Sentry is configured to implement the applicable required TLS settings in NIST PUB SP 800-52.

1. Log in to Sentry.
2. Go to Settings >> Services >> Sentry.
3. For each of the following configurations, follow the step 4 procedure:
a. Incoming SSL configuration
b. Outgoing SSL configuration
c. UEM SSL configuration
d. Access SSL configuration
4. Verify only TLS 1.2 is selected.

If any other protocol is selected, this is a finding.

For more information, go to the "Sentry 9.8.0 guide for Core" and refer the main section "Standalone Sentry Settings", which includes subsections on how TLS 1.2 is set as the default protocol:
1. Incoming SSL configuration
2. Outgoing SSL configuration
3. UEM SSL configuration
4. Access SSL configuration

Sentry conforms to the NIST SP 800-52 TLS settings by setting TLS 1.2 by default.

Vulnerability Number

V-251013

Documentable

False

Rule Version

MOIS-AL-000180

Severity Override Guidance

Verify the Sentry is configured to implement the applicable required TLS settings in NIST PUB SP 800-52.

1. Log in to Sentry.
2. Go to Settings >> Services >> Sentry.
3. For each of the following configurations, follow the step 4 procedure:
a. Incoming SSL configuration
b. Outgoing SSL configuration
c. UEM SSL configuration
d. Access SSL configuration
4. Verify only TLS 1.2 is selected.

If any other protocol is selected, this is a finding.

For more information, go to the "Sentry 9.8.0 guide for Core" and refer the main section "Standalone Sentry Settings", which includes subsections on how TLS 1.2 is set as the default protocol:
1. Incoming SSL configuration
2. Outgoing SSL configuration
3. UEM SSL configuration
4. Access SSL configuration

Sentry conforms to the NIST SP 800-52 TLS settings by setting TLS 1.2 by default.

Check Content Reference

M

Target Key

5439