STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must use a FIPS-validated cryptographic module to generate cryptographic hashes.

DISA Rule

SV-251420r1004747_rule

Vulnerability Number

V-251420

Group Title

SRG-APP-000514-UEM-000389

Rule Version

IMIC-11-012400

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the MDM server to use a FIPS 140-2 validated cryptographic module.

On the MDM console, do the following:
1. SSH to MobileIron Core Server from any SSH client.
2. Enter the administrator credentials you set when you installed MobileIron Core.
3. Enter enable.
4. When prompted, enter the enable secret you set when you installed MobileIron Core.
5. Enter configure terminal.
6. Enter the following command to enable FIPS: fips
7. Enter the following command to proceed with the necessary reload: do reload

Check Contents

On the MDM console, do the following:
1. SSH to MobileIron Core Server from any SSH client.
2. Enter the administrator credentials you set when you installed MobileIron Core.
3. Enter show fips.
4. Verify "FIPS 140 mode is enabled" is displayed.

If the MobileIron Server Core does not report that FIPS mode is enabled, this is a finding.

Vulnerability Number

V-251420

Documentable

False

Rule Version

IMIC-11-012400

Severity Override Guidance

On the MDM console, do the following:
1. SSH to MobileIron Core Server from any SSH client.
2. Enter the administrator credentials you set when you installed MobileIron Core.
3. Enter show fips.
4. Verify "FIPS 140 mode is enabled" is displayed.

If the MobileIron Server Core does not report that FIPS mode is enabled, this is a finding.

Check Content Reference

M

Target Key

5445