MKE must be configured to integrate with an Enterprise Identity Provider.
DISA Rule
SV-260909r1015769_rule
Vulnerability Number
V-260909
Group Title
SRG-APP-000023-CTR-000055
Rule Version
CNTR-MK-000030
Severity
CAT II
CCI(s)
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000016 - Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account.
- CCI-000017 - Disable accounts when the accounts have been inactive for the organization-defined time-period.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
- CCI-004061 - For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-002145 - Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-001953 - Accepts Personal Identity Verification-compliant credentials.
- CCI-002009 - Accept Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-002699 - Perform verification of the correct operation of organization-defined security functions: when the system is in an organization-defined transitional state; upon command by a user with appropriate privileges; and/or on an organization-defined frequency.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
Weight
10
Fix Recommendation
To configure Identity Provider, log in to the MKE web UI and navigate to admin >> Admin Settings >> Authentication & Authorization >> Identity Provider Integration section.
To configure LDAP:
Click the radial button to set LDAP to "Enabled".
In the "LDAP Server" subsection set the following:
- "LDAP Server URL" to the URL for the organization's AD or LDAP server (URL must be https).
- "Reader DN" with the DN of the account used to search the LDAP entries.
- "Reader Password" with the password for the Reader account.
Click "Save".
To configure SAML, click the radial button to set SAML to "Enabled".
Enter URL in the "Service Provider Metadata URL" field.
Upload the certificate bundle for the IdP provider in "Root Certificates Bundle".
In the "SAML Service Provider" section, enter the "MKE IP address" in the MKE Host field.
Click "Save".
Check Contents
Verify that Enterprise Identity Provider integration is enabled and properly configured in the MKE Admin Settings.
1. Log in to the MKE web UI and navigate to admin >> Admin Settings >> Authentication & Authorization.
If LDAP or SAML are not set to "Enabled", this is a finding.
2. Identity Provider configurations:
When using LDAP, ensure the following are set:
- LDAP/AD server's URL.
- Reader DN.
- Reader Password.
When using SAML:
In the "SAML IdP Server" section, ensure the following:
- URL for the identity provider exists in the "IdP Metadata URL" field.
- Skip TLS Verification is unchecked.
- Root Certificate Bundle is filled.
In the "SAML Service Provider" section, ensure the MKE Host field has the MKE UI IP address.
If the Identity Provider configurations do not match the System Security Plan (SSP), this is a finding.
Vulnerability Number
V-260909
Documentable
False
Rule Version
CNTR-MK-000030
Severity Override Guidance
Verify that Enterprise Identity Provider integration is enabled and properly configured in the MKE Admin Settings.
1. Log in to the MKE web UI and navigate to admin >> Admin Settings >> Authentication & Authorization.
If LDAP or SAML are not set to "Enabled", this is a finding.
2. Identity Provider configurations:
When using LDAP, ensure the following are set:
- LDAP/AD server's URL.
- Reader DN.
- Reader Password.
When using SAML:
In the "SAML IdP Server" section, ensure the following:
- URL for the identity provider exists in the "IdP Metadata URL" field.
- Skip TLS Verification is unchecked.
- Root Certificate Bundle is filled.
In the "SAML Service Provider" section, ensure the MKE Host field has the MKE UI IP address.
If the Identity Provider configurations do not match the System Security Plan (SSP), this is a finding.
Check Content Reference
M
Target Key
5595