STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must use encryption when using LDAP for authentication.

DISA Rule

SV-279440r1191106_rule

Vulnerability Number

V-279440

Group Title

SRG-APP-000172-AS-000121

Rule Version

NXAC-AS-000035

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix VM application server to use an Active Directory server to authenticate individual users.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Add an Active Directory or OpenLDAP server to the directory list using SSL encrypted ports 636 or 3269.

Check Contents

Confirm the Nutanix Envoy Reverse Proxy is set to use encryption when using LDAP.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Verify an Active Directory or OpenLDAP server is on the directory list.

If an Active Directory or OpenLDAP servers are not using ports 636 or 3269, which are SSL encrypted, this is a finding.

Vulnerability Number

V-279440

Documentable

False

Rule Version

NXAC-AS-000035

Severity Override Guidance

Confirm the Nutanix Envoy Reverse Proxy is set to use encryption when using LDAP.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to Authentication settings.
4. Verify an Active Directory or OpenLDAP server is on the directory list.

If an Active Directory or OpenLDAP servers are not using ports 636 or 3269, which are SSL encrypted, this is a finding.

Check Content Reference

M

Target Key

5729