UCF STIG Viewer Logo

The mobile operating systems Wi-Fi module must use EAP-TLS authentication when authenticating to DoD WLAN authentication servers.


Overview

Finding ID Version Rule ID IA Controls Severity
V-33093 SRG-OS-000116-MOS-000070 SV-43491r1_rule Medium
Description
Without strong mutual authentication a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and then provide authentication credentials and other sensitive information. EAP-TLS is strong mutual authentication leveraging a public key infrastructure. Its use greatly mitigates risk associated with authentication transactions.
STIG Date
Mobile Operating System Security Requirements Guide 2013-07-03

Details

Check Text ( C-41352r1_chk )
Verify the mobile operating system configuration supports EAP-TLS. Support for non-TLS authentication methods, such as EAP-PEAP or EAP-SIM, does not meet the requirement. If the operating system does not support EAP-TLS when authenticating to DoD WLAN authentication servers, this is a finding.
Fix Text (F-36993r1_fix)
Configure the mobile operating system's Wi-Fi module to use EAP-TLS authentication when authenticating to DoD WLAN authentication servers.