Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-33093 | SRG-OS-000116-MOS-000070 | SV-43491r1_rule | Medium |
Description |
---|
Without strong mutual authentication a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and then provide authentication credentials and other sensitive information. EAP-TLS is strong mutual authentication leveraging a public key infrastructure. Its use greatly mitigates risk associated with authentication transactions. |
STIG | Date |
---|---|
Mobile Operating System Security Requirements Guide | 2013-07-03 |
Check Text ( C-41352r1_chk ) |
---|
Verify the mobile operating system configuration supports EAP-TLS. Support for non-TLS authentication methods, such as EAP-PEAP or EAP-SIM, does not meet the requirement. If the operating system does not support EAP-TLS when authenticating to DoD WLAN authentication servers, this is a finding. |
Fix Text (F-36993r1_fix) |
---|
Configure the mobile operating system's Wi-Fi module to use EAP-TLS authentication when authenticating to DoD WLAN authentication servers. |