UCF STIG Viewer Logo

When configuring Central Administration, the port number selected must comply with DoD Ports and Protocol Management (PPSM) program requirements.


Overview

Finding ID Version Rule ID IA Controls Severity
V-28170 SHPT-00-000480 SV-37769r2_rule Medium
Description
During the installation of Microsoft SharePoint, the Central Administration Web site is established on a randomly-assigned TCP port by default. Allowing a randomly-assigned default may result in use of a port which violates DoD policy or conflicts with ports already in use. Use of certain well-known ports may also result in slow operational responses or may expose the application to denial of service attacks.
STIG Date
MS SharePoint 2010 Security Technical Implementation Guide 2019-01-02

Details

Check Text ( C-36997r4_chk )
1. In Central Administrator, view the URL in the address bar of the browser.
2. The URL includes a colon which is followed by the port number.
3. Mark as a finding if the port number used is not allowed in accordance with DoD PPSM policy or is less than 1024.
Fix Text (F-32261r3_fix)

1. Open the SharePoint 2010 Management Shell (Start > All Programs > Microsoft SharePoint 2010 Products > SharePoint 2010 Management Shell).
2. Change the port number to a PPSM approved port which does not conflict with existing port usage by using the following command:
–Set -SPCentralAdministration -Port .
3. Press Enter to save.