STIGQter STIGQter: STIG Summary: F5 NGINX Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Nov 2025:

NGINX must be configured to expire cached authenticators after an organization-defined time period.

DISA Rule

SV-278401r1171955_rule

Vulnerability Number

V-278401

Group Title

SRG-APP-000400

Rule Version

NGNX-APP-001690

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Determine path to NGINX config file:

# nginx -qT | grep "# configuration"
# configuration file /etc/nginx/nginx.conf:

Note: The default NGINX configuration is "/etc/nginx/nginx.conf", though various files may also be included.

Edit the config and set a timeout on any keyval storing credentials:

keyval_zone zone=oidc_access_tokens:1M state=/var/lib/nginx/state/oidc_access_tokens.json timeout=1h;

Restart NGINX:

nginx -s reload

Check Contents

If a keyval store is not used to store tokens, this is not applicable.

Determine path to NGINX config file:

# nginx -qT | grep "# configuration"
# configuration file /etc/nginx/nginx.conf:

Note: The default NGINX configuration is "/etc/nginx/nginx.conf", though various files may also be included.

Determine if a keyval store is used and no timeout is specified:

grep keyval <location of config>

Example:

keyval_zone zone=oidc_access_tokens:1M state=/var/lib/nginx/state/oidc_access_tokens.json timeout=1h;

If a timeout is not specified to an organization defined timeout value, this is a finding.

Vulnerability Number

V-278401

Documentable

False

Rule Version

NGNX-APP-001690

Severity Override Guidance

If a keyval store is not used to store tokens, this is not applicable.

Determine path to NGINX config file:

# nginx -qT | grep "# configuration"
# configuration file /etc/nginx/nginx.conf:

Note: The default NGINX configuration is "/etc/nginx/nginx.conf", though various files may also be included.

Determine if a keyval store is used and no timeout is specified:

grep keyval <location of config>

Example:

keyval_zone zone=oidc_access_tokens:1M state=/var/lib/nginx/state/oidc_access_tokens.json timeout=1h;

If a timeout is not specified to an organization defined timeout value, this is a finding.

Check Content Reference

M

Target Key

5720