STIGUI
V-285632CAT I — High severitySV-285632r1274303_rule

The Content Analysis System (CAS) must be configured to use a centralized authentication server to securely map PKI-authenticated identities to administrative user accounts and roles.

Rule version BCAS-ND-001460 · STIG v1 · 2026-09-16

Discussion

Without mapping the PKI certificate to a unique user account, the ability to determine the identities of individuals or the status of their nonrepudiation is considerably impacted during forensic analysis. A strength of using PKI as multifactor authentication (MFA) is that it can help ensure only the assigned individual is using their associated user account. This can only be accomplished if the network device is configured to enforce the relationship which binds PKI certificates to unique user accounts.

Local accounts (accounts created, stored, and maintained locally on the network device) should be avoided in lieu of using a centrally managed directory service. Local accounts empower the same workgroup who will be operating the network infrastructure to also control and manipulate access methods, thus creating operational autonomy. This undesirable approach breaks the concept of separation of duties. Additionally, local accounts are susceptible to poor cyber hygiene because they create another user database that must be maintained by the operator, whose primary focus is on running the network. Such examples of poor hygiene include dormant accounts that are not disabled or deleted, employees who have left the organization but whose accounts are still present, periodic password and hash rotation, password complexity shortcomings, increased exposure to insider threat, etc. For reasons such as this, local users on network devices are frequently the targets of cyber-attacks. Instead, organizations should explore examples of centrally managed account services. These examples include the implementation of AAA concepts like the use of external Remote Authentication Dial-In User Service (RADIUS) and Lightweight Directory Access Protocol (LDAP) directory service brokers.

Satisfies: SRG-APP-000177-NDM-000263, SRG-APP-000516-NDM-000336

Check

Verify secure LDAP is configured and PKI identities are mapped to roles with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config authentication". 4. Verify LDAP is enabled by checking for the setting "authentication ldap enable". 5. Verify the LDAP URL utilizes a secure connection by checking that it begins with "ldaps://". 6. Verify the PKI identity mapping is configured by checking for the setting "authentication ldap public-key-attribute altSecurityIdentities". 7. Verify at least one group is mapped to an administrative role (e.g., "role admin").

If LDAP is not enabled, the URL does not use "ldaps://", or the PKI-to-role mappings are missing, this is a finding.

Fix

Configure secure LDAP and map PKI identities to administrative roles with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and enter the password. 3. Enter "configure terminal". 4. Enable LDAP authentication by entering "authentication ldap enable". 5. Define the secure LDAP URL by entering "authentication ldap url ldaps://[Site URL]". (Replace [Site URL] with the LDAPS server address.) 6. Configure the necessary LDAP connection and search parameters by entering the following commands (replacing the bracketed text with site-specific DNs): "authentication ldap search-credentials username [Full DN of Service Account]" "authentication ldap search-credentials password" (press Enter and provide the password) "authentication ldap user-search username userPrincipalName" "authentication ldap user-search base [User Search Base]" "authentication ldap role-search username userPrincipalName" "authentication ldap role-search base [Role Search Base]" "authentication ldap role-search attribute memberOf" 7. Map the PKI identity attribute by entering "authentication ldap public-key-attribute altSecurityIdentities". 8. Map the enterprise group to the CAS administrator role by entering "authentication ldap group [Site Admin Group DN]". 9. Enter "role admin". 10. Enter "exit" and then "exit" again to leave configuration mode.

Identifiers

Group ID
V-285632
Group title
SRG-APP-000177-NDM-000263
Rule ID
SV-285632r1274303_rule
Check ID
C-90312r1273013_chk
Fix ID
F-90217r1274302_fix