STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must prohibit the use of cached authenticators after an organization-defined time period.

DISA Rule

SV-269795r1052420_rule

Vulnerability Number

V-269795

Group Title

SRG-APP-000400-NDM-000313

Rule Version

OS10-NDM-000760

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the OS10 Switch to prohibit the use of cached authenticators after an organization-defined time period:

OS10(config)# rest authentication token validity {minutes}

Check Contents

Review the OS10 Switch configuration to determine if it prohibits the use of cached authenticators after an organization-defined time period.

Verify the rest authentication token validity setting is configured. If no entry is displayed, the default is 120 minutes.

OS10# show running-configuration | grep "rest authentication token validity"
rest authentication token validity 60

If cached authenticators are used after an organization-defined time period, this is a finding.

Vulnerability Number

V-269795

Documentable

False

Rule Version

OS10-NDM-000760

Severity Override Guidance

Review the OS10 Switch configuration to determine if it prohibits the use of cached authenticators after an organization-defined time period.

Verify the rest authentication token validity setting is configured. If no entry is displayed, the default is 120 minutes.

OS10# show running-configuration | grep "rest authentication token validity"
rest authentication token validity 60

If cached authenticators are used after an organization-defined time period, this is a finding.

Check Content Reference

M

Target Key

5666