UCF STIG Viewer Logo

The mobile operating system must authenticate devices before establishing remote network (e.g., VPN) connections using bidirectional cryptographically based authentication between devices.


Overview

Finding ID Version Rule ID IA Controls Severity
KNOX-13-002600 KNOX-13-002600 KNOX-13-002600_rule Medium
Description
Without strong mutual authentication a mobile device may connect to an unauthorized network. In many cases, the user may falsely believe that the device is connected to an authorized network and then provide authentication credentials and other sensitive information. A strong bidirectional cryptographically based authentication method mitigates this risk.
STIG Date
Samsung Knox Android 1.0 STIG 2013-05-03

Details

Check Text ( C-KNOX-13-002600_chk )
This check procedure is performed using an MDM tool.

Check that the appropriate setting is configured on the MDM server.

For example, on the Fixmo Sentinel Administration Console:
1. Ask the MDM administrator to display the "Disable Insecure VPN Connections" checkbox in the "Android Knox Restrictions" rule.
2. Verify the checkbox is selected.

If the "Disable Insecure VPN Connections" checkbox is not selected, this is a finding.
Fix Text (F-KNOX-13-002600_fix)
Configure the operating system to authenticate devices before establishing remote connections.

For example, on the Fixmo Sentinel Administration Console, check the "Disable Insecure VPN Connections" checkbox in the "Android Knox Restrictions" rule.