STIGUI
V-285619CAT II — Medium severitySV-285619r1273165_rule

The Content Analysis System (CAS) must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

Rule version BCAS-ND-001330 · STIG v1 · 2026-09-16

Discussion

Authentication for administrative (privileged level) access to the device is required at all times. An account can be created on the device's local database for use when the authentication server is down or connectivity between the device and the authentication server is not operable. This account is referred to as the account of last resort since it is intended to be used as a last resort and when immediate administrative access is absolutely necessary.

The account of last resort logon credentials must be stored in a sealed envelope and kept in a safe. The safe must be periodically audited to verify the envelope remains sealed. The signature of the auditor and the date of the audit should be added to the envelope as a record. Administrators should secure the credentials and disable the root account (if possible) when not needed for system administration functions.

Check

Verify only one local account exists and the console-account is set to "fallback-only" with the following steps:

Verify local accounts via Web UI: 1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> Users >> Local Users. 3. Scroll down to the "Users" section and verify only the documented and approved account of last resort exists.

Verify fallback configuration via CLI: 1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config authentication". 3. Review the output for "authentication management console-account".

If any user other than the documented and approved local account of last resort exists, or if the console-account configuration states "always" instead of "fallback-only", this is a finding.

Fix

Configure the local account to "fallback-only" and remove all unauthorized local users with the following steps:

Remove unauthorized users via Web UI: 1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> Users >> Local Users. 3. Scroll down to the "Users" section. Note: Only the documented and approved account of last resort is permitted. 4. Delete all other local users by selecting the user, clicking "Delete User", and selecting "Yes" when prompted to confirm. 5. Click "Save Changes".

Configure fallback-only via CLI: 1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Set the console account to fallback-only by entering "authentication management console-account fallback-only". 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode. 6. To verify the change, attempt to log in with the local admin account while the external authentication server is reachable. It should prompt for a password but not permit successful login.

Identifiers

Group ID
V-285619
Group title
SRG-APP-000148-NDM-000346
Rule ID
SV-285619r1273165_rule
Check ID
C-90299r1273110_chk
Fix ID
F-90204r1273164_fix