STIGQter STIGQter: STIG Summary: Unified Endpoint Management Server Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

The UEM server, when using PKI-based authentication, must enforce authorized access to the corresponding private key.

DISA Rule

SV-234380r617355_rule

Vulnerability Number

V-234380

Group Title

SRG-APP-000176

Rule Version

SRG-APP-000176-UEM-000107

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the UEM server, when using PKI-based authentication, to enforce authorized access to the corresponding private key.

Check Contents

Requirement is Not Applicable when UEM server is configured to use DoD Central Directory Service for administrator account authentication.

Verify the he UEM server, when using PKI-based authentication, enforces authorized access to the corresponding private key.

If the UEM server, when using PKI-based authentication, does not enforce authorized access to the corresponding private key, this is a finding

Vulnerability Number

V-234380

Documentable

False

Rule Version

SRG-APP-000176-UEM-000107

Severity Override Guidance

Requirement is Not Applicable when UEM server is configured to use DoD Central Directory Service for administrator account authentication.

Verify the he UEM server, when using PKI-based authentication, enforces authorized access to the corresponding private key.

If the UEM server, when using PKI-based authentication, does not enforce authorized access to the corresponding private key, this is a finding

Check Content Reference

M

Target Key

5269

Comments