SV-86079r1_rule
V-71455
SRG-NET-000392-ALG-000143
CAGW-GW-000790
CAT II
10
There should be no fix for this, as by default the CA API Gateway is configured to disallow remote logons by the root user and detect when an attempt to logon as root has occurred.
Using an SSH client, attempt to log on to the CA API Gateway using the root user. The attempt will fail as root logons from a remote SSH client are disabled by default.
On the main console of the CA API Gateway, log on with the root user and notice the message stating "There were 'x' failed login attempts..." and "Last failed login: date time from address on ssh:notty".
If the logon is allowed or the message does not appear, this is a finding.
V-71455
False
CAGW-GW-000790
Using an SSH client, attempt to log on to the CA API Gateway using the root user. The attempt will fail as root logons from a remote SSH client are disabled by default.
On the main console of the CA API Gateway, log on with the root user and notice the message stating "There were 'x' failed login attempts..." and "Last failed login: date time from address on ssh:notty".
If the logon is allowed or the message does not appear, this is a finding.
M
3049