STIGQter STIGQter: STIG Summary: HPE Nimble Storage Array NDM Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The HPE Nimble must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.

DISA Rule

SV-252197r997780_rule

Vulnerability Number

V-252197

Group Title

SRG-APP-000516-NDM-000336

Rule Version

HPEN-NM-000120

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

To configure AD, run the following commands:

"userauth --join <domain> --domain_user administrator" and enter the domain administrator password to join <domain>.

"userauth --list" will show the domain and its status.

To create a mapping between an AD group and one of the four device RBAC roles, run the following command:

"userauth --add_group <domain_group> --domain <domain> --role {administrator|poweruser|operator|guest}"

This command allows any member of <domain_group> in <domain> AD domain to log in to the device with one of the selected roles.

To display the group to role mappings, run "userauth --list_group --domain <domain>".

Check Contents

Run the command "userauth --list".

If the output is "No domains configured", this is a finding.

Vulnerability Number

V-252197

Documentable

False

Rule Version

HPEN-NM-000120

Severity Override Guidance

Run the command "userauth --list".

If the output is "No domains configured", this is a finding.

Check Content Reference

M

Target Key

5460