Dragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication.
DISA Rule
SV-271034r1057745_rule
Vulnerability Number
V-271034
Group Title
SRG-APP-000402
Rule Version
DRAG-OT-001750
Severity
CAT II
CCI(s)
- CCI-002009 - Accept Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-002010 - Electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-001953 - Accepts Personal Identity Verification-compliant credentials.
- CCI-001954 - Electronically verifies Personal Identity Verification-compliant credentials.
- CCI-000185 - For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
- CCI-000186 - For public key-based authentication, enforce authorized access to the corresponding private key.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
Weight
10
Fix Recommendation
Configure an SSO proxy service using LDAP to provide PKI credentials.
Check Contents
Verify that Dragos is configured to use the DOD CAC or other PKI credential to log in to the application.
Log in to the application.
If DOD CAC or other PKI is not configured, this is a finding.
Vulnerability Number
V-271034
Documentable
False
Rule Version
DRAG-OT-001750
Severity Override Guidance
Verify that Dragos is configured to use the DOD CAC or other PKI credential to log in to the application.
Log in to the application.
If DOD CAC or other PKI is not configured, this is a finding.
Check Content Reference
M
Target Key
5675