STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS must authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.

DISA Rule

SV-266976r1039949_rule

Vulnerability Number

V-266976

Group Title

SRG-APP-000395-NDM-000347

Rule Version

ARBA-ND-000347

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
ntp authentication-key (keyid #> sha1 <plaintext key>
ntp trusted-key <keyid #>
ntp server <first fqdn, ipv4, or ipv6 address> key <keyid #>
ntp server <second fqdn, ipv4, or ipv6 address> key <keyid #>
ntp authenticate
write memory

Check Contents

1. Verify the AOS configuration with the following command:
show ntp status

If "Authentication" shows "disabled", this is a finding.

2. show running-config | include ntp

If at least one trusted NTP authentication-key is not configured and at least one NTP server configured to use the key, this is a finding.

Vulnerability Number

V-266976

Documentable

False

Rule Version

ARBA-ND-000347

Severity Override Guidance

1. Verify the AOS configuration with the following command:
show ntp status

If "Authentication" shows "disabled", this is a finding.

2. show running-config | include ntp

If at least one trusted NTP authentication-key is not configured and at least one NTP server configured to use the key, this is a finding.

Check Content Reference

M

Target Key

5648