Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36083 | SRG-APP-128-MDM-083-MDM | SV-47474r1_rule | High |
Description |
---|
If mutual authentication is not performed between the MDM server and the provisioned devices during the provisioning, rogue devices could connect to the MDM server or a rogue MDM server could connect to the device. In either case, an integrity issue would exist within the mobility infrastructure. The mutual authentication ensures that the MDM server and the device are known entities before provisioning. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44322r1_chk ) |
---|
Review the MDM server configuration to determine whether there is mutual authentication between the provisioning server and the provisioned device. If additional assurance is required, validate the provisioning server will not provision software and data to an unauthorized device and that an authorized device will not connect to an unauthorized provisioning server (e.g., a valid provisioning server with its credentials temporarily removed for the test). If either the device does not authenticate the provisioning infrastructure, or vice versa, this is a finding. |
Fix Text (F-40613r1_fix) |
---|
Configure the MDM server to ensure authentication occurs at the provisioning server prior to accepting provisioned software. |