STIGQter STIGQter: STIG Summary: Citrix XenDesktop 7.x Delivery Controller Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Apr 2020:

Delivery Controller must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.

DISA Rule

SV-96117r1_rule

Vulnerability Number

V-81403

Group Title

SRG-APP-000001

Rule Version

CXEN-DC-000005

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open Citrix Studio, right-click a Delivery Group, and choose "Edit Delivery Group".

Uncheck the following check box: "Give access to unauthenticated (anonymous) users; no credentials are required to access StoreFront".

A Citrix Studio administrator account is needed to perform above fix.

Check Contents

Open Citrix Studio, right-click a Delivery Group, and choose "Edit Delivery Group".

Verify the following check box is not checked: "Give access to unauthenticated (anonymous) users; no credentials are required to access StoreFront".

If the check box is checked, this is a finding.

A Citrix Studio administrator account is needed to perform this check. Performing this check does not impact system reliability or availability.

Vulnerability Number

V-81403

Documentable

False

Rule Version

CXEN-DC-000005

Severity Override Guidance

Open Citrix Studio, right-click a Delivery Group, and choose "Edit Delivery Group".

Verify the following check box is not checked: "Give access to unauthenticated (anonymous) users; no credentials are required to access StoreFront".

If the check box is checked, this is a finding.

A Citrix Studio administrator account is needed to perform this check. Performing this check does not impact system reliability or availability.

Check Content Reference

M

Target Key

3291

Comments