STIGUI
V-285651CAT I — High severitySV-285651r1274318_rule

The Content Analysis System (CAS) must utilize a centralized authentication server via a secure, encrypted connection to authenticate all administrative users prior to granting access.

Rule version BCAS-ND-001880 · STIG v1 · 2026-09-16

Discussion

Allowing administrators to rely solely on local, device-specific accounts makes it difficult to manage identities and maintain a consistent security posture across the enterprise. In a large DoW environment, managing individual accounts on every network device is labor-intensive and prone to error, such as failing to disable an account when a member leaves the organization. Furthermore, using unencrypted protocols (like plain LDAP) to transmit administrative credentials allows for the interception of passwords via packet sniffing.

To mitigate these risks, the CAS must be configured to utilize a centralized authentication server (such as Active Directory) via Secure LDAP (LDAPS). This architecture ensures that management access is centrally governed by enterprise security policies and that all authentication traffic is cryptographically protected, satisfying DoW mandates for secure, centralized identity management.

Satisfies: SRG-APP-000516-NDM-000336, SRG-APP-000156-NDM-000250, SRG-APP-000400-NDM-000313, SRG-APP-000820-NDM-000170

Check

Verify the CAS is configured to use Secure LDAP (LDAPS) as the centralized authentication server with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config authentication". 4. Verify the centralized authentication mechanism is active by checking for the setting "authentication ldap enable". 5. Verify the connection to the authentication server is encrypted by checking that the URL setting begins with "ldaps://".

If LDAP is not enabled, or if the URL is using unencrypted "ldap://" instead of secure "ldaps://", this is a finding.

Fix

Configure the CAS to use LDAPS for centralized administrative authentication with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and enter the password. 3. Enter "configure terminal". 4. Enable the centralized authentication mechanism by entering "authentication ldap enable". 5. Enforce an encrypted connection to the authentication server by entering "authentication ldap url ldaps://[Site URL]". (Replace [Site URL] with the organization's LDAPS server address.) 6. Enter "exit" and then "exit" again to leave configuration mode.

Identifiers

Group ID
V-285651
Group title
SRG-APP-000516-NDM-000336
Rule ID
SV-285651r1274318_rule
Check ID
C-90331r1273070_chk
Fix ID
F-90236r1274318_fix