STIGUI
V-285645CAT II — Medium severitySV-285645r1274307_rule

The Content Analysis System (CAS) must be configured to authenticate Network Time Protocol (NTP) sources using authentication with Federal Information Processing Standards (FIPS)-compliant algorithms.

Rule version BCAS-ND-001700 · STIG v1 · 2026-09-16

Discussion

If NTP is not authenticated, an attacker can introduce a rogue NTP server. This rogue server can then be used to send incorrect time information to network devices, which will make log timestamps inaccurate and affect scheduled actions.

NTP authentication is used to prevent this tampering by authenticating the time source.

Check

Review the CAS configuration to verify it authenticates NTP sources using authentication with FIPS-compliant algorithms with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show clock". 4. Review the output for the NTP symmetric-key authentication status.

Note: CAS is limited to SHA1 for NTP authentication, and incurs a permanent CAT III finding as it is not FIPS compliant. SHA1 partially reduces the risk but cannot fully mitigate it.

If the CAS is not configured to authenticate NTP sources with a FIPS-compliant algorithm, this is a finding.

Fix

Configure the CAS to authenticate NTP sources using authentication with FIPS-compliant algorithms with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable", enter the password, and enter "configure terminal". 3. Configure the authentication key by entering "ntp symmetric-key [NUMBER] algorithm sha1 secret [NTPKEY]". (Replace [NUMBER] with the ID of the key on the NTP server and [NTPKEY] with the SHA1 NTP preshared key.) 4. Enforce authentication on the primary NTP server by entering "ntp server [FIRSTNTPSERVER] symmetric-key [NUMBER]". (Replace [NUMBER] with the ID of the key and [FIRSTNTPSERVER] with the IP address or hostname of the primary NTP server.) 5. Enforce authentication on the secondary NTP server by entering "ntp server [SECONDNTPSERVER] symmetric-key [NUMBER]". (Replace [NUMBER] with the ID of the key and [SECONDNTPSERVER] with the IP address or hostname of the secondary NTP server.) 6. Enter "exit" and then "exit" again to leave configuration mode.

Identifiers

Group ID
V-285645
Group title
SRG-APP-000395-NDM-000347
Rule ID
SV-285645r1274307_rule
Check ID
C-90325r1273052_chk
Fix ID
F-90230r1274306_fix