STIGQter STIGQter: STIG Summary: Axonius Federal Systems Ax-OS Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Ax-OS must protect the authenticity of communications sessions.

DISA Rule

SV-276013r1122689_rule

Vulnerability Number

V-276013

Group Title

SRG-APP-000219

Rule Version

AXOS-00-000065

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Select the gear icon (System Settings) >> Privacy and Security >> Certificate and Encryption.

Under Certificate Verifications Settings, select "Use OCSP".

Under SSL Trust & CA Settings, select "Use custom certificate" and configure for a DOD PKI (or other AO-approved certificate).

Under Mutual TLS Settings, enable the "Enable mutual TLS" slide bar. Check the "Enforce client certificate validation" box.

Under Encryption Settings, ensure the "Allow legacy SSL cipher suites for adapters" box is unchecked.

Check Contents

Select the gear icon (System Settings) >> Privacy and Security >> Certificate and Encryption.

Under SSL Certificate, if the certificate has not been changed from the self-signed default certificate, unless otherwise approved by the authorizing official (AO), this is a finding.

Under Certificate Verifications Settings, if "Use OCSP" is not selected, this is a finding.

Under SSL Trust & CA Settings, if "Use custom certificate" is not selected and configured for a DOD PKI (or other AO-approved certificate), this is a finding.

Under Mutual TLS Settings, if the "Enable mutual TLS" slide bar is not enabled, and the "Enforce client certificate validation" box is unchecked, this is a finding.

Under Encryption Settings, if the "Allow legacy SSL cipher suites for adapters" is checked, this is a finding.

Vulnerability Number

V-276013

Documentable

False

Rule Version

AXOS-00-000065

Severity Override Guidance

Select the gear icon (System Settings) >> Privacy and Security >> Certificate and Encryption.

Under SSL Certificate, if the certificate has not been changed from the self-signed default certificate, unless otherwise approved by the authorizing official (AO), this is a finding.

Under Certificate Verifications Settings, if "Use OCSP" is not selected, this is a finding.

Under SSL Trust & CA Settings, if "Use custom certificate" is not selected and configured for a DOD PKI (or other AO-approved certificate), this is a finding.

Under Mutual TLS Settings, if the "Enable mutual TLS" slide bar is not enabled, and the "Enforce client certificate validation" box is unchecked, this is a finding.

Under Encryption Settings, if the "Allow legacy SSL cipher suites for adapters" is checked, this is a finding.

Check Content Reference

M

Target Key

5710