Rule version BCAS-ND-001140 · STIG v1 · 2026-09-16
This requirement supports nonrepudiation of actions taken by an administrator and is required to maintain the integrity of the configuration management process. All configuration changes to the network device are logged, and administrators authenticate with two-factor authentication before gaining administrative access. Together, these processes will ensure the administrators can be held accountable for the configuration changes they implement.
To meet this requirement, the network device must log administrator access and activity.
Verify the system is configured to extract the correct Principal Name from the certificate for identity mapping with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config authentication". 4. Review the output for the following exact setting: "certificate-auth user-regex "PN=(.*?)(,|/|$)"
If "certificate-auth user-regex" is not set exactly as specified above, this is a finding.
Configure the system to map the authenticated identity with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and then enter the password. 3. Enter "configure terminal". 4. Set the certificate user regular expression by entering "authentication certificate-auth user-regex "PN=(.*?)(,|/|$)". 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.