STIGQter STIGQter: STIG Summary: AvePoint DocAve 6 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Aug 2022:

DocAve must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.

DISA Rule

SV-253518r836529_rule

Vulnerability Number

V-253518

Group Title

SRG-APP-000427

Rule Version

DCAV-00-000192

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure DocAve to ensure that it uses PKI certificates obtained from a DoD-approved internal or external certificate authority. There are three different settings in DocAve that are related to certificates:
- The DocAve web server for the web UI;
- The DocAve Manager communication certificate for communicate with DocAve Agents;
- The DocAve Agent communication certificate for communicate with DocAve Manager.

Configure the DocAve Web Site certificate setting.
- On the DocAve 6 Manager server, open Internet Information Services (IIS) Manager.
- In IIS Manager, expand the Sites node in the Connections panel on the left and find DocAve 6 Control Service Web Site. The default name of DocAve Control Web Site is DocAve6.
- Click "Bindings" in the Actions panel on the right to open the Site Bindings window.
- Click "Edit" in Site Bindings window to open the Edit Site Binding window.
- Select the DoD-approved certificate.
- Click "OK" to save settings.

Configure the DocAve Manager communication certificate setting.
- On the DocAve 6 Manager server, open DocAve 6 Manager Configuration Tool.
- Click "Advanced Configuration" on the left.
- Click the "User-defined Certificate" radio button, then click "Select Certificate" to open the Windows Security window.
- Select the DoD-approved certificate.
- Click "OK" to save settings.

Configure the DocAve Agent communication certificate setting.
- On the DocAve 6 Agent server, open DocAve 6 Agent Configuration Tool.
- Navigate to the SSL Certificate panel.
- Click the "User-defined Certificate" radio button, then click "Select Certificate" to open the Windows Security window.
- Select the DoD-approved certificate.
- Click "OK" to save settings.

Check Contents

There are three different settings in DocAve that are related to certificates:
- The DocAve web server for the web UI;
- The DocAve Manager communication certificate for communicate with DocAve Agents;
- The DocAve Agent communication certificate for communicate with DocAve Manager.

Check the DocAve Web Site certificate setting.
- On the DocAve 6 Manager server, open Internet Information Services (IIS) Manager.
- In IIS Manager, expand the Sites node in the Connections panel on the left and find DocAve 6 Control Service Web Site. The default name of DocAve Control Web Site is DocAve6.
- Click "Bindings" in the Actions panel on the right to open the Site Bindings window.
- Click "Edit" in Site Bindings window to open the Edit Site Binding window.
- Verify the certificate information.

If the certificate used is not a DoD- (or AO-) approved certificate, this is a finding.

Check the DocAve Manager communication certificate setting.
- On the DocAve 6 Manager server, open DocAve 6 Manager Configuration Tool.
- Click "Advanced Configuration" on the left.
- Verify the certificate information.

If the certificate used is not a DoD approved certificate, this is a finding.

Check the DocAve Agent communication certificate setting.
- On the DocAve 6 Agent server, open DocAve 6 Agent Configuration Tool.
- Navigate to the SSL Certificate panel.
- Verify the certificate information.

If the certificate used is not a DoD-approved certificate, this is a finding.

Vulnerability Number

V-253518

Documentable

False

Rule Version

DCAV-00-000192

Severity Override Guidance

There are three different settings in DocAve that are related to certificates:
- The DocAve web server for the web UI;
- The DocAve Manager communication certificate for communicate with DocAve Agents;
- The DocAve Agent communication certificate for communicate with DocAve Manager.

Check the DocAve Web Site certificate setting.
- On the DocAve 6 Manager server, open Internet Information Services (IIS) Manager.
- In IIS Manager, expand the Sites node in the Connections panel on the left and find DocAve 6 Control Service Web Site. The default name of DocAve Control Web Site is DocAve6.
- Click "Bindings" in the Actions panel on the right to open the Site Bindings window.
- Click "Edit" in Site Bindings window to open the Edit Site Binding window.
- Verify the certificate information.

If the certificate used is not a DoD- (or AO-) approved certificate, this is a finding.

Check the DocAve Manager communication certificate setting.
- On the DocAve 6 Manager server, open DocAve 6 Manager Configuration Tool.
- Click "Advanced Configuration" on the left.
- Verify the certificate information.

If the certificate used is not a DoD approved certificate, this is a finding.

Check the DocAve Agent communication certificate setting.
- On the DocAve 6 Agent server, open DocAve 6 Agent Configuration Tool.
- Navigate to the SSL Certificate panel.
- Verify the certificate information.

If the certificate used is not a DoD-approved certificate, this is a finding.

Check Content Reference

M

Target Key

5472