STIGQter STIGQter: STIG Summary: HPE Nimble Storage Array NDM Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The HPE Nimble must obtain its public key certificates from an appropriate certificate policy through an approved service provider.

DISA Rule

SV-252198r1001013_rule

Vulnerability Number

V-252198

Group Title

SRG-APP-000516-NDM-000344

Rule Version

HPEN-NM-000130

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To create and import a custom, CA-signed certificate, follow these steps:

1. Type "cert --gen custom-csr". Copy the displayed CSR and submit it to an appropriate signing authority.
2. Type "cert --import custom-ca" and paste the PEM-encoded CA certificate chain as input to the command.
3. Type "cert --import custom" and paste the signed certificate obtained from the CA.

Check Contents

Type "cert --list". Review the output to confirm that the custom-ca and custom certificates exist, and the "Use" values specified for HTTPS and APIS are both "custom". If not, this is a finding.

Vulnerability Number

V-252198

Documentable

False

Rule Version

HPEN-NM-000130

Severity Override Guidance

Type "cert --list". Review the output to confirm that the custom-ca and custom certificates exist, and the "Use" values specified for HTTPS and APIS are both "custom". If not, this is a finding.

Check Content Reference

M

Target Key

5460