STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be configured to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.

DISA Rule

SV-266078r1024610_rule

Vulnerability Number

V-266078

Group Title

SRG-APP-000131-NDM-000243

Rule Version

F5BI-DM-300039

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP console, type the following commands:

tmsh modify /sys db liveinstall.checksig value "enable"
tmsh save sys config

Check Contents

From the BIG-IP console, type the following command:

tmsh list /sys db liveinstall.checksig value

Note: This must return a value of "enable".

If the db variable is not set to "enable", this is a finding.

Vulnerability Number

V-266078

Documentable

False

Rule Version

F5BI-DM-300039

Severity Override Guidance

From the BIG-IP console, type the following command:

tmsh list /sys db liveinstall.checksig value

Note: This must return a value of "enable".

If the db variable is not set to "enable", this is a finding.

Check Content Reference

M

Target Key

5639