STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must use multifactor authentication (MFA) for access to privileged and nonprivileged accounts by enabling client authentication.

DISA Rule

SV-279439r1191103_rule

Vulnerability Number

V-279439

Group Title

SRG-APP-000825-AS-000180

Rule Version

NXAC-AS-000034

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Prism Element WebUI to require client authentication.

1. Log in to Prism Element.
2. Click the gear in the upper-right corner and navigate to Authentication.
3. Click the "Client" tab.
4. Select the "Configure Client Chain Certificate" check box.
5. Click "Choose File", browse to and select a client chain certificate to upload, and then click "Open" to upload the certificate.
6. Click "Enable Client Authentication".

Check Contents

Confirm the Prism Element WebUI requires client authentication.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication.
4. Click the "Client" tab.
5. Verify client authentication is enabled.

If client authentication is not enabled, this is a finding.

Vulnerability Number

V-279439

Documentable

False

Rule Version

NXAC-AS-000034

Severity Override Guidance

Confirm the Prism Element WebUI requires client authentication.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication.
4. Click the "Client" tab.
5. Verify client authentication is enabled.

If client authentication is not enabled, this is a finding.

Check Content Reference

M

Target Key

5729