Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-246847 | HYCU-CM-000003 | SV-246847r768205_rule | Medium |
Description |
---|
For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority will suffice. |
STIG | Date |
---|---|
HYCU for Nutanix Security Technical Implementation Guide | 2021-08-03 |
Check Text ( C-50279r768203_chk ) |
---|
Open a new HYCU Web UI browser tab and verify there is no warning prompt before proceeding to the Web UI logon page. If a warning appears in the web browser stating "Not secure", this is a finding. |
Fix Text (F-50233r768204_fix) |
---|
Log on to the HYCU Web UI and generate a CSR within the gear menu and "SSL Certificates" menu. Submit this CSR to a DoD PKI authority to have a new certificate created. Note: By default, HYCU is configured with a self-signed certificate, but this can be replaced with a DoD-issued certificate. This certificate can be configured by logging on to the HYCU Web UI, going to the gear menu and "SSL Certificates" menu, and importing the DoD-issued certificate. |