UCF STIG Viewer Logo

The Google Search Appliance must support organizational requirements to enforce password encryption for transmission.


Overview

Finding ID Version Rule ID IA Controls Severity
V-60785 GSAP-00-000565 SV-75237r1_rule Medium
Description
Passwords need to be protected at all times and encryption is the standard method for protecting passwords during transmission.
STIG Date
Google Search Appliance Security Technical Implementation Guide 2015-07-07

Details

Check Text ( C-61709r1_chk )
Open the GSA Web Admin Console at https::8443.

Login to the GSA management interface.

Navigate to "Administration", select "SSL Settings".

Under "Other Settings" - If "Use HTTPS when serving both public and secure results" is checked, this is not a finding.
Fix Text (F-66467r1_fix)
Open the GSA Web Admin Console at https::8443.

Login to the GSA management interface.

Navigate to "Administration", select "SSL Settings".

Under "Other Settings" - Enable option "Use HTTPS when serving both public and secure results".

Click Save.