AvePoint Fly Server Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 5 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- FLYS-00-000005
- Vuln IDs
-
- V-283924
- Rule IDs
-
- SV-283924r1206887_rule
Checks: C-88489r1206885_chk
Check the Fly Server Manager session setting: - Log on to Fly Server Manager with an admin account. - On the Management >> General Settings page, click the "System Option" tab. - Verify the "Allow concurrent sessions from multiple servers for the same account" setting. If this setting is checked, this is a finding.
Fix: F-88394r1206886_fix
Configure the Fly Server Manager session setting: - Log on to Fly Server Manager with an admin account. - On the Management >> General Settings page, click the "System Option" tab. - Uncheck the "Allow concurrent sessions from multiple servers for the same account" setting. - Save the setting.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000017
- Version
- FLYS-00-000015
- Vuln IDs
-
- V-283925
- Rule IDs
-
- SV-283925r1206871_rule
Checks: C-88490r1206869_chk
Check the Fly Server security settings: - Log on to Fly Server Manager with the admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Navigate to "User Settings". - Verify the "Deactivate a user after 35 days of inactivity" option is checked. If this option is not checked, this is a finding.
Fix: F-88395r1206870_fix
Configure the Fly Server security settings: - Log on to Fly Server Manager with the administrator account. - On the Management >> General Settings page, click the "Security Option" tab. - Navigate to "User Settings", then click "Deactivate a user after 35 days of inactivity" option. - Set 35 days or other values as required. - Save the setting.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- FLYS-00-000020
- Vuln IDs
-
- V-283926
- Rule IDs
-
- SV-283926r1206132_rule
Checks: C-88491r1206130_chk
Check the logon configuration in Fly Server Manager: - Access the VM or server where the Fly Server manager is installed. - Find the installation location of Fly Server manager. - Open the "TimerService.exe.config" file in ...\APElements\FLY\Manager\Control\bin. - Check the key "FailedLogOnLimitationCount". If the value is not "3", this is a finding.
Fix: F-88396r1206131_fix
Configure the logon configuration in Fly Server Manager: - Access the VM or server where the Fly Server manager is installed. - Find the installation location of Fly Server manager. - Open the "TimerService.exe.config" file in ...\APElements\FLY\Manager\Control\bin. - Find following node and set the value to "3": <add key="FailedLogOnLimitationCount" value="3" />
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- FLYS-00-000035
- Vuln IDs
-
- V-283927
- Rule IDs
-
- SV-283927r1206911_rule
Checks: C-88492r1206133_chk
Open the Fly Server console in a browser and note the port number in the URL. Fly Server uses ports 20100 and 20101 by default for Manager and Agent internal communication. If the ports used are organization-defined to be in use by another system, this is a finding.
Fix: F-88397r1206134_fix
Configure the internal communication ports for Fly Server Manager and Agent. - Install Fly Server Manager and Agent. - Set Manager Access URL and Internal Communication Port setting, set to ports that are not organization-defined to be in use by another system.
- RMF Control
- Severity
- H
- CCI
- CCI-004046
- Version
- FLYS-00-000055
- Vuln IDs
-
- V-283928
- Rule IDs
-
- SV-283928r1223356_rule
Checks: C-88493r1206888_chk
Fly Server must be integrated with Active Directory (AD) and Azure AD (AAD) for automated account management. Check the Fly Server Account Manager setting to verify AD Integration or AAD Integration is enabled: - Log on to Fly Server with an admin account. - On the Management >> Account Manager page, click "Authentication Manager". - Navigate to AD Integration or AAD Integration. - Verify the AD Integration or AAD Integration option is enabled. If the AD Integration or AAD Integration option is not enabled, this is a finding.
Fix: F-88398r1206137_fix
Configure the Fly Server Account Manager setting to ensure AD Integration or AAD Integration is enabled: - Log on to Fly Server with an admin account. - On the Management >> Account Manager page, click "Authentication Manager". - Navigate to AD Integration or AAD Integration. - Set the Action of AD Integration or AAD Integration to "Enable". - Add an AD domain after AD integration is enabled. - Save the setting. Add AD user/group or AAD user/group to Account Manager; realize automated mechanisms through AD or AAD account management functions.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- FLYS-00-000065
- Vuln IDs
-
- V-283929
- Rule IDs
-
- SV-283929r1206891_rule
Checks: C-88494r1206890_chk
Fly Server must be integrated with Active Directory (AD) and Azure AD (AAD) for automated account management. Check the Fly Server Account Manager setting to verify AD Integration or AAD Integration is enabled: - Log on to Fly Server with an admin account. - On the Management >> Account Manager page, click "Authentication Manager". - Navigate to AD Integration or AAD Integration. - Verify the AD Integration or AAD Integration option is enabled. If the AD Integration or AAD Integration option is not enabled, this is a finding.
Fix: F-88399r1206140_fix
Configure the Fly Server Account Manager setting to ensure AD Integration or AAD Integration is enabled: - Log on to Fly Server with an admin account. - On the Management >> Account Manager page, click "Authentication Manager". - Navigate to AD Integration or AAD Integration. - Set the Action of AD Integration or AAD Integration to "Enable". - Add an AD domain after AD integration is enabled. - Save the setting. Add AD user/group or AAD user/group to Account Manager; realize automated mechanisms through AD or AAD account management functions.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- FLYS-00-000070
- Vuln IDs
-
- V-283930
- Rule IDs
-
- SV-283930r1206893_rule
Checks: C-88495r1206873_chk
Check the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Verify the Password Complexity setting. If the Password complexity setting is not set to Custom, with checkboxes enabled for uppercase letters, lowercase letters, numerical digits, and special characters, this is a finding.
Fix: F-88400r1206892_fix
Configure the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Set the Password Complexity setting to Custom, select four checkboxes to enforce that the password must contain four character types: uppercase letters, lowercase letters, digits, and special characters.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- FLYS-00-000075
- Vuln IDs
-
- V-283931
- Rule IDs
-
- SV-283931r1206876_rule
Checks: C-88496r1206875_chk
Check the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Verify the Password Complexity setting. If the Password complexity setting is not set to Custom, with checkboxes enabled for uppercase letters, lowercase letters, numerical digits, and special characters, this is a finding.
Fix: F-88401r1206146_fix
Configure the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Set the Password Complexity setting to Custom, select four checkboxes to enforce that the password must contain four character types: uppercase letters, lowercase letters, digits, and special characters.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- FLYS-00-000080
- Vuln IDs
-
- V-283932
- Rule IDs
-
- SV-283932r1206878_rule
Checks: C-88497r1206877_chk
Check the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Verify the Password Complexity setting. If the Password complexity setting is not set to Custom, with checkboxes enabled for uppercase letters, lowercase letters, numerical digits, and special characters, this is a finding.
Fix: F-88402r1206149_fix
Configure the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Set the Password Complexity setting to Custom, select four checkboxes to enforce that the password must contain four character types: uppercase letters, lowercase letters, digits, and special characters.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- FLYS-00-000085
- Vuln IDs
-
- V-283933
- Rule IDs
-
- SV-283933r1206880_rule
Checks: C-88498r1206879_chk
Check the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Verify the Password Complexity setting. If the Password complexity setting is not set to Custom, with checkboxes enabled for uppercase letters, lowercase letters, numerical digits, and special characters, this is a finding.
Fix: F-88403r1206152_fix
Configure the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Set the Password Complexity setting to Custom, select four checkboxes to enforce that the password must contain four character types: uppercase letters, lowercase letters, digits, and special characters.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- FLYS-00-000090
- Vuln IDs
-
- V-283934
- Rule IDs
-
- SV-283934r1206156_rule
Checks: C-88499r1206154_chk
Check the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Verify the Change Password setting is set to "New password cannot have consecutively same 8 characters as previous password". If this option is unchecked, this is a finding.
Fix: F-88404r1206155_fix
Configure the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Set Change Password setting, check option "New password cannot have consecutively same 8 characters as previous password".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- FLYS-00-000095
- Vuln IDs
-
- V-283935
- Rule IDs
-
- SV-283935r1206159_rule
Checks: C-88500r1206157_chk
Check the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Verify the Change Password setting option "Change the password once only within 24 hours" is checked. If this option is unchecked, this is a finding.
Fix: F-88405r1206158_fix
Configure the Fly Server Manager security configuration: - Log on to Fly Server with an admin account. - On the Management >> General Settings page, click the "Security Option" tab. - Check "Change the password once only within 24 hours" to set the Change Password setting.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- FLYS-00-000100
- Vuln IDs
-
- V-283936
- Rule IDs
-
- SV-283936r1206162_rule
Checks: C-88501r1206160_chk
Check the Fly Server Manager session setting: - Log on to Fly Server Manager with an admin account. - On the Management >> General Settings page, click the "System Option" tab. - Verify the "Session Will Expire After Inactivity for:" setting is selected. If this setting is not 10 minutes, this is a finding.
Fix: F-88406r1206161_fix
Configure the Fly Server Manager session setting: - Log on to Fly Server Manager with an admin account. - On the Management >> General Settings page, click the "System Option" tab. - Set the session setting to "Session Will Expire After Inactivity for 10 minutes".
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000015
- Version
- FLYS-00-000105
- Vuln IDs
-
- V-283937
- Rule IDs
-
- SV-283937r1206895_rule
Checks: C-88502r1206894_chk
Check the Fly Server Manager Notification setting: - Log on to Fly Server Manager with an admin account. - On the Management >> Email Configuration, click the "Email Notification" tab. - Verify "Send account management notification emails to:" is selected. If this setting is not set, this is a finding.
Fix: F-88407r1206164_fix
Configure the Fly Server Manager Notification setting: - Log on to Fly Server Manager with admin account. - On the Management >> Email Configuration, click the "Email Notification" tab. - Select the "Send account management notification emails to:" setting. - Save the setting.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000766
- Version
- FLYS-00-000110
- Vuln IDs
-
- V-283938
- Rule IDs
-
- SV-283938r1223357_rule
Checks: C-88503r1206166_chk
Once Active Directory is configured in FLYS-00-000055, all local users must be removed. Check the Fly Server User settings: - On the Management >> Account Manager tab, view the list of users. - User accounts tied to an Active Directory domain will be defined as [domainname]\[username]. If any of the users listed are not tied to Active Directory, this is a finding.
Fix: F-88408r1206167_fix
Once Active Directory is configured in FLYS-00-000055, remove all local users: - On the Management >> Account Manager tab, remove all local users.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000766
- Version
- FLYS-00-000115
- Vuln IDs
-
- V-283939
- Rule IDs
-
- SV-283939r1223358_rule
Checks: C-88504r1206169_chk
Once Active Directory is configured in FLYS-00-000055, local authentication must be disabled. - On the Management >> Account Manager tab, click "Authentication Manager". If the slide-bar for Local System is active, this is a finding.
Fix: F-88409r1206170_fix
Once Active Directory is configured in FLYS-00-000055, disable local authentication: - On the Management >> Account Manager tab, click "Authentication Manager". - Disable the Local System slide-bar.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- FLYS-00-000140
- Vuln IDs
-
- V-283941
- Rule IDs
-
- SV-283941r1223361_rule
Checks: C-88506r1223360_chk
To validate the web certificate: 1. Run the following command to check sslcert: curl.exe -vI https://<FLY host>:<port>/ 2. If there is "The certificate chain was issued by an authority that is not trusted." in the output, this is a finding. To validate the communication certificate: 1. Log in to the agent server. 2. Open the file "…\APElements\FLY\Agent\bin\AgentCommonVCEnv.config" and find the value of "agentSSLThumbprint". 3. Open the certmgr and find the certificate. 4. If the certificate is not a DoW PKI (or other AO-approved) certificate, this is a finding.
Fix: F-88411r1206896_fix
To replace the web certificate: 1. Prepare trusted certificate (pfx file). 2. Install the pfx certificate on the FLY Manager server. 3. Run the following command to replace the sslcert binding: netsh http delete sslcert ipport=0.0.0.0:<FLY Manager Port default:20100> netsh http add sslcert ipport=0.0.0.0:<FLY Manager Port default:20100> certhash=<THUMBPRINT> appid={b8a60d7f-c976-4416-b5af-f9e36cae4dae} 4. Update the value of the node "WebCertThumbprint" in the file …\FLY\Manager\Control\bin\TimerService.exe.config. 5. Restart "FLY Timer Service". To replace the communication certificate: 1. Prepare trusted communication certificate (pfx file). 2. Install the pfx certificate on all FLY servers (agent and manager servers). 3. On the FLY Manager server, update the value of "CertThumbprint" in the file "…\FLY\Manager\Control\bin\TimerService.exe.config". 4. Restart "FLY Timer Service". 5. Log in to the agent servers. 6. Run the following command to replace the sslcert binding: netsh http delete sslcert ipport=0.0.0.0:<FLY Agent Port Default:20101> netsh http add sslcert ipport=0.0.0.0:<FLY Agent Port Default:20101> certhash=<THUMBPRINT> appid={b8a60d7f-c976-4416-b5af-f9e36cae4dae} 7. Update the thumbprint in the following config file: "agentSSLThumbprint" in …\APElements\FLY\Agent\bin\AgentCommonVCEnv.config "clientCertificate" and "serviceCertificate" in …\APElements\FLY\Agent\bin\AgentCommonWCFBehaviors.config "clientCertificate" and "serviceCertificate" in …\APElements\FLY\Agent\bin\CommonDataTransfer.config 8. Restart "FLY Agent Service".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- FLYS-00-000150
- Vuln IDs
-
- V-283942
- Rule IDs
-
- SV-283942r1223359_rule
Checks: C-88507r1206898_chk
Check the Fly Server control database type in the configuration file of Fly Server manager: Open "<Program Files>\APElements\FLY\Manager\Control\bin\TimerService.exe.config" with a text editor. If the value of "ConfigDatabaseType" is" SQLite", the system has been configured to use built-in database when installing Fly Server manager. If the value of "ConfigDatabaseType" is "SQLite", this is a finding. If the value of "ConfigDatabaseInstance" points to a path local to the host where Fly Server resided, this is a finding.
Fix: F-88412r1206179_fix
Configure Fly Server to use a MS SQL server database when installing Fly Server manager. The MS-SQL server cannot reside on the same host as the Fly Server application.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-002169
- Version
- FLYS-00-000805
- Vuln IDs
-
- V-284007
- Rule IDs
-
- SV-284007r1207111_rule
Checks: C-88571r1206371_chk
RBAC hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured. Check the Fly Server Role settings: - Log on to Fly Server Manager with an admin account. - On the Management >> Role Manager tab, view the configured roles. If only one role exists, this is a finding. Check the role assignments: - On the Management >> Account Manager tab, view the Role column. If only one role is assigned, this is a finding. If only one user exists in the list of users, this is a finding.
Fix: F-88476r1207111_fix
RBAC hierarchy is to be defined by the AO. Separation of duties must be configured. Configure the Fly Server Role settings: - Log on to Fly Server Manager with an admin account. - On the Management >> Role Manager tab, configure two or more roles. Configure the role assignments: - On the Management >> Account Manager tab, assign a unique role to two or more users. Add users if necessary.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- FLYS-00-000950
- Vuln IDs
-
- V-284030
- Rule IDs
-
- SV-284030r1206442_rule
Checks: C-88594r1206440_chk
Check the Fly Server update service configuration: - Log on to Fly Server with an admin account. - On the Management >> System Information page, click "Service Configuration". - Verify "Auto check new version" is set to "Weekly". If the "Auto check new version" is not set to "Weekly", this is a finding.
Fix: F-88499r1206441_fix
Configure the Fly Server update service configuration: - Log on to Fly Server with an admin account. - On the Management >> System Information page, click "Service Configuration". - Set "Auto check new version" to "Weekly". - Click "Save".
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- FLYS-00-000951
- Vuln IDs
-
- V-284031
- Rule IDs
-
- SV-284031r1206445_rule
Checks: C-88595r1206443_chk
Check the Fly Server release version: - Log on to Fly Server with an admin account. - On the Management >> System Information page, click "Check for a new version". - If a new version is available, the number will be displayed. Note the version number. - Compare the new version number with the version history documented on AvePoint's website. If no updated version information is displayed via "Check for a new version", the system is up to date. There is no finding. If the available version number is more than 30 days old, this is a finding.
Fix: F-88500r1206444_fix
Upgrade the system: - Log on to Fly Server with an admin account. - On the Management >> System Information page, click "Check for a new version". - If a new version is available, the number will be displayed. Note the version number. - Compare the new version number with the version history documented on AvePoint's website. Upgrade to the latest version within 30 days of release.
- RMF Control
- SA-22
- Severity
- H
- CCI
- CCI-003376
- Version
- FLYS-00-000952
- Vuln IDs
-
- V-284032
- Rule IDs
-
- SV-284032r1206448_rule
Checks: C-88596r1206446_chk
Check the Fly Server release version: - Log on to Fly Server with an admin account. - On the Management >> System Information page, note the version number. - Compare the version number with the product end of life information documented on AvePoint's website. If the version information is displayed is not supported by the vendor, this is a finding.
Fix: F-88501r1206447_fix
Upgrade the system to a supported version.