Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
A DoD approved VPN, or gateway/proxy, must be leveraged to access StoreFront from a remote network. This VPN, or gateway, must handle user authentication and tunneling of StoreFront traffic. The VPN, or gateway, must meet the DoD encryption requirements, such as FIPS 140-2, for the environment. If no VPN, or gateway/proxy, is used for remote access to StoreFront, this is a finding. If the VPN, or gateway/proxy, does not authenticate the remote user before providing access to StoreFront, this is a finding. If the VPN, or gateway/proxy, fails to meet the DoD encryption requirements for the environment, this is a finding.
Implement a DoD approved VPN, or gateway/proxy, that will authenticate user access and tunnel/proxy traffic to StoreFront. Ensure the VPN, or gateway/proxy, is configured to authenticate the user before accessing the environment, and meets the DoD encryption requirements, such as FIPS 140-2, for the environment.
Open the Citrix StoreFront management console and select the "Store" node in the left pane. For each Store listed, select the store and perform the following: 1) From the Actions menu item, click "Manage Authentication Methods". 2) Ensure only "Smart card" is selected. If using remote access "Pass-through from NetScaler Gateway" may also be selected. If the "Smart Card" method is not selected, or if other methods are selected, this is a finding. If "Pass-through from NetScaler Gateway" is selected, this is not a finding.
Open the Citrix StoreFront management console and select the "Store" node in the left pane. For each Store listed, select the store and perform the following: 1) From the Actions menu item, click "Manage Authentication Methods". 2) Check "Smart card" and uncheck any other authentication methods. If using remote access, select "Pass-through from NetScaler Gateway".