UCF STIG Viewer Logo

Applications using multifactor authentication when accessing non-privileged accounts via the network must utilize replay resistant authentication.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35305 SRG-APP-000157-AS-NA SV-46592r1_rule Medium
Description
An authentication process resists replay attacks if it is impractical to achieve a successful authentication by recording and replaying a previous authentication message. Rationale for non-applicability: All accounts on the AS are used for management of the application server or the applications themselves. The AS is only accessed by authorized administrators serving in roles used to manage specific functionality of the server. This requirement is NA. Non-privileged accounts will not be present.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43674r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-39851r1_fix)
The requirement is NA. No fix is required.