STIGUI
V-284529CAT I — High severitySV-284529r1244935_rule

The Ivanti Policy Secure must be configured to transmit only encrypted representations of passwords.

Rule version IVPS-NM-000035 · STIG v1 · 2026-07-09

Discussion

Multifactor authentication (MFA) is required for all administrative and user accounts on network devices, except for an account of last resort and (where applicable) a root account. Passwords should only be used when MFA using public key infrastructure (PKI) is not available, and for the account of last resort and root account.

Check

1. In the Web UI, navigate to System >> Configuration >> Inbound SSL Options. 2. Under "Allowed SSL and TLS Version", verify "Accept only TLS 1.2 (maximize security)" is selected. 3. Navigate to System >> Configuration >> Outbound SSL Options. 4. View the setting for "Allowed SSL and TLS Version".

If "Accept only TLS 1.2 (maximize security)" is not checked, this is a finding.

Fix

1. In the Web UI, navigate to System >> Configuration >> Inbound SSL Options. 2. Under "Allowed SSL and TLS Version", check the box for "Accept only TLS 1.2 (maximize security)". 3. Click "Save Changes". 4. Click "Proceed" to accept the cipher change. 5. Navigate to System >> Configuration >> Outbound SSL Options. 6. Under "Allowed SSL and TLS Version", check the box for "Accept only TLS 1.2 (maximize security)". 7. Click "Save Changes". 8. Click "Proceed" to accept the cipher change.

Identifiers

Group ID
V-284529
Group title
SRG-APP-000172-NDM-000259
Rule ID
SV-284529r1244935_rule
Check ID
C-89094r1244218_chk
Fix ID
F-88999r1244219_fix