Rule version BCAS-ND-001880 · STIG v1 · 2026-09-16
Allowing administrators to rely solely on local, device-specific accounts makes it difficult to manage identities and maintain a consistent security posture across the enterprise. In a large DoW environment, managing individual accounts on every network device is labor-intensive and prone to error, such as failing to disable an account when a member leaves the organization. Furthermore, using unencrypted protocols (like plain LDAP) to transmit administrative credentials allows for the interception of passwords via packet sniffing.
To mitigate these risks, the CAS must be configured to utilize a centralized authentication server (such as Active Directory) via Secure LDAP (LDAPS). This architecture ensures that management access is centrally governed by enterprise security policies and that all authentication traffic is cryptographically protected, satisfying DoW mandates for secure, centralized identity management.
Satisfies: SRG-APP-000516-NDM-000336, SRG-APP-000156-NDM-000250, SRG-APP-000400-NDM-000313, SRG-APP-000820-NDM-000170
Verify the CAS is configured to use Secure LDAP (LDAPS) as the centralized authentication server with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config authentication". 4. Verify the centralized authentication mechanism is active by checking for the setting "authentication ldap enable". 5. Verify the connection to the authentication server is encrypted by checking that the URL setting begins with "ldaps://".
If LDAP is not enabled, or if the URL is using unencrypted "ldap://" instead of secure "ldaps://", this is a finding.
Configure the CAS to use LDAPS for centralized administrative authentication with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and enter the password. 3. Enter "configure terminal". 4. Enable the centralized authentication mechanism by entering "authentication ldap enable". 5. Enforce an encrypted connection to the authentication server by entering "authentication ldap url ldaps://[Site URL]". (Replace [Site URL] with the organization's LDAPS server address.) 6. Enter "exit" and then "exit" again to leave configuration mode.