STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions.

DISA Rule

SV-251417r1004744_rule

Vulnerability Number

V-251417

Group Title

SRG-APP-000427-UEM-000298

Rule Version

IMIC-11-010200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install DoD digital certificates.

Configure the MDM server. System Manager >> Security >> Certificate Management >> Portal HTTPS. Install DOD certificate chain.

Check Contents

Verify the MDM server is configured with TLS server certificate chain to a DOD certificate Authority.

Go into the Certificate Manager >> System Manager >> Security >> Certificate Management >> Portal HTTPS. Verify DoD certificates are installed.

If DoD digital certificates are not installed on Core, this is a finding.

Vulnerability Number

V-251417

Documentable

False

Rule Version

IMIC-11-010200

Severity Override Guidance

Verify the MDM server is configured with TLS server certificate chain to a DOD certificate Authority.

Go into the Certificate Manager >> System Manager >> Security >> Certificate Management >> Portal HTTPS. Verify DoD certificates are installed.

If DoD digital certificates are not installed on Core, this is a finding.

Check Content Reference

M

Target Key

5445