STIGQter STIGQter: STIG Summary: AvePoint DocAve 6 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Aug 2022:

DocAve must use multifactor authentication for network access to privileged accounts.

DISA Rule

SV-253515r836520_rule

Vulnerability Number

V-253515

Group Title

SRG-APP-000149

Rule Version

DCAV-00-000056

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure DocAve to use Smart Card Authentication. Settings must be configured in IIS and DocAve. The IIS configuration under DCAV-00-000057 should be performed first.

Log on to DocAve with admin account.
- On the Control Panel page, in the Authentication Manager section, click "Authentication Manager".
- Click "Enable" in the Action column of the Client Certificate Authentication row to enable client certificate authentication.
- Click "Enable" in the Action column of the Windows Authentication row to enable Windows Authentication.
- Back to the Control Panel page, in the Account Manager section, click "Account Manager".
- Click "Users-Add User".
- Select Client Certificate User from the drop-down list in the "What kind of user would you like to add?" field.
- Specify the user in the Windows User/Group Name field.
- Add this user to one or more DocAve groups.
- Save the settings.

Check Contents

DocAve supports Client Certificate Authentication for multi-factor authentication, which requires both Windows Authentication and Client Certificate Authentication enabled in DocAve. Settings must be configured in IIS and DocAve. The IIS configuration under DCAV-00-000057 should be performed first.

Check the DocAve Client Certificate Authentication configuration.
- Log on to DocAve with admin account.
- On the Control Panel page, in the Authentication Manager section, click "Authentication Manager".
- Verify that "Client Certificate Authentication" is enabled.

If "Client Certificate Authentication" is not enabled, this is a finding.

Check the DocAve Windows Authentication configuration.
- Log on to DocAve with admin account.
- On the Control Panel page, in the Authentication Manager section, click "Authentication Manager".
- Verify that "Windows Authentication" is enabled.

If "Windows Authentication" is not enabled, this is a finding.

Vulnerability Number

V-253515

Documentable

False

Rule Version

DCAV-00-000056

Severity Override Guidance

DocAve supports Client Certificate Authentication for multi-factor authentication, which requires both Windows Authentication and Client Certificate Authentication enabled in DocAve. Settings must be configured in IIS and DocAve. The IIS configuration under DCAV-00-000057 should be performed first.

Check the DocAve Client Certificate Authentication configuration.
- Log on to DocAve with admin account.
- On the Control Panel page, in the Authentication Manager section, click "Authentication Manager".
- Verify that "Client Certificate Authentication" is enabled.

If "Client Certificate Authentication" is not enabled, this is a finding.

Check the DocAve Windows Authentication configuration.
- Log on to DocAve with admin account.
- On the Control Panel page, in the Authentication Manager section, click "Authentication Manager".
- Verify that "Windows Authentication" is enabled.

If "Windows Authentication" is not enabled, this is a finding.

Check Content Reference

M

Target Key

5472