STIGUI
V-285614CAT II — Medium severitySV-285614r1273163_rule

The Content Analysis System (CAS) must map the authenticated identity to the user account for PKI-based authentication.

Rule version BCAS-ND-001140 · STIG v1 · 2026-09-16

Discussion

This requirement supports nonrepudiation of actions taken by an administrator and is required to maintain the integrity of the configuration management process. All configuration changes to the network device are logged, and administrators authenticate with two-factor authentication before gaining administrative access. Together, these processes will ensure the administrators can be held accountable for the configuration changes they implement.

To meet this requirement, the network device must log administrator access and activity.

Check

Verify the system is configured to extract the correct Principal Name from the certificate for identity mapping with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config authentication". 4. Review the output for the following exact setting: "certificate-auth user-regex "PN=(.*?)(,|/|$)"

If "certificate-auth user-regex" is not set exactly as specified above, this is a finding.

Fix

Configure the system to map the authenticated identity with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and then enter the password. 3. Enter "configure terminal". 4. Set the certificate user regular expression by entering "authentication certificate-auth user-regex "PN=(.*?)(,|/|$)". 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285614
Group title
SRG-APP-000080-NDM-000220
Rule ID
SV-285614r1273163_rule
Check ID
C-90294r1272959_chk
Fix ID
F-90199r1273162_fix