STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by nonrepudiation.

DISA Rule

SV-279423r1191055_rule

Vulnerability Number

V-279423

Group Title

SRG-APP-000080-AS-000045

Rule Version

NXAC-AS-000013

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix VM application server Prism Element WebUI to require client authentication.

1. Log in to Prism Element.
2. Click the gear in the upper-right corner and navigate to "Authentication".
3. Click the "Client" tab.
4. Select the "Configure Client Chain Certificate" check box.
5. Click the "Choose File" button, browse to and select a client chain certificate to upload, and then click the "Open" button to upload the certificate.
6. Click "Enable Client Authentication".

Check Contents

Confirm the Nutanix VM application server Prism Element WebUI requires client authentication.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to the "Authentication" section.
4. Click the "Client" tab.
5. Verify "Client Authentication" is enabled.

If Client Authentication (CAC Auth) is not enabled, this is a finding.

Vulnerability Number

V-279423

Documentable

False

Rule Version

NXAC-AS-000013

Severity Override Guidance

Confirm the Nutanix VM application server Prism Element WebUI requires client authentication.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to the "Authentication" section.
4. Click the "Client" tab.
5. Verify "Client Authentication" is enabled.

If Client Authentication (CAC Auth) is not enabled, this is a finding.

Check Content Reference

M

Target Key

5729