STIGQter STIGQter: STIG Summary: IBM DataPower Network Device Management Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Oct 2017:

The DataPower Gateway must display an explicit logout message to administrators indicating the reliable termination of authenticated communications sessions.

DISA Rule

SV-79615r1_rule

Vulnerability Number

V-65125

Group Title

SRG-APP-000297-NDM-000281

Rule Version

WSDP-NM-000083

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DataPower Gateway to use a custom user interface XML file that can be configured to provide the desired logout message to administrators.

From the WebGUI, go to Administration >> Device >> System Settings and associate the custom interface file with the "Customer User Interface" field.

A template of the custom user interface file may be found on the DataPower file system at store:///schemas/dp-user-interface.xsd.

Check Contents

To verify, log out of a web session and an SSH command line session.

Upon logout from the web interface, the DataPower Gateway displays the IBM DataPower Login panel. This is a clear indication that the administrator has logged out.

Upon logout from an administrative SSH command line session, the following message is displayed: "Unauthorized access prohibited. logon:" A clear indication that logout has occurred.

If this message is not present, this is a finding.

Vulnerability Number

V-65125

Documentable

False

Rule Version

WSDP-NM-000083

Severity Override Guidance

To verify, log out of a web session and an SSH command line session.

Upon logout from the web interface, the DataPower Gateway displays the IBM DataPower Login panel. This is a clear indication that the administrator has logged out.

Upon logout from an administrative SSH command line session, the following message is displayed: "Unauthorized access prohibited. logon:" A clear indication that logout has occurred.

If this message is not present, this is a finding.

Check Content Reference

M

Target Key

2861

Comments