STIGQter STIGQter: STIG Summary: HYCU Protege Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The HYCU virtual appliance must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.

DISA Rule

SV-268237r1038754_rule

Vulnerability Number

V-268237

Group Title

SRG-APP-000149-NDM-000247

Rule Version

HYCU-ND-000210

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure Identity Provider authentication by adding one or more Identity Providers as authentication sources in HYCU.

This allows users to log in to the HYCU web user interface with their Identity Provider accounts or, if certificate authentication is enabled, with a client certificate or a smart card (CAC authentication).

Log in to the HYCU Web UI, select the gear menu, and choose the "Identity Providers" option.

Configure Identity Provider by specifying the required setting. For example, if configuring Active Directory IDP, provide the domain and required LDAP URL to allow HYCU to use AD users and groups for access to the Web UI.

When using certificate authentication using client certificate or smart card (CAC authentication), ensure "Service Account" is specified in the Active Directory configuration and "Enable Certificate Authentication" is enabled.

Check Contents

Log in to the HYCU Web UI, select the gear menu, and then choose the Identity Providers option.

Verify that at least one Identity Provider authentication server is configured.

If no Identity Provider is configured, this is a finding.

When using certificate authentication using client certificate or smart card (CAC authentication), verify "Enable Certificate Authentication" is enabled.

If "Enable Certification Authentication" is not enabled, this is a finding.

Vulnerability Number

V-268237

Documentable

False

Rule Version

HYCU-ND-000210

Severity Override Guidance

Log in to the HYCU Web UI, select the gear menu, and then choose the Identity Providers option.

Verify that at least one Identity Provider authentication server is configured.

If no Identity Provider is configured, this is a finding.

When using certificate authentication using client certificate or smart card (CAC authentication), verify "Enable Certificate Authentication" is enabled.

If "Enable Certification Authentication" is not enabled, this is a finding.

Check Content Reference

M

Target Key

5660