Google Search Appliance Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 2 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- GSAP-00-000030
- Vuln IDs
-
- V-60395
- Rule IDs
-
- SV-74825r1_rule
Checks: C-61359r2_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Log on to the GSA management interface. Click Administration >> Remote Support. If "Enable SSH for Remote Support" is unchecked, this is not a finding.
Fix: F-66053r3_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Click Administration >> Remote Support. Uncheck the option "Enable SSH for Remote Support". Click Update.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000015
- Version
- GSAP-00-000075
- Vuln IDs
-
- V-60717
- Rule IDs
-
- SV-75169r1_rule
Checks: C-61663r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Click Administration >> LDAP Setup. If valid LDAP information is entered, this is not a finding.
Fix: F-66397r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Click Administration >> LDAP Setup. Click Create. In the LDAP Directory Server Address section, enter the following information: Host - LDAP directory server's host name, which is a fully-qualified domain name or an IPv4 address. Port number (optional) - the port number where the LDAP server listens for requests. If the LDAP server does not allow anonymous users to search, enter the following user credentials that the search appliance uses when logging into the LDAP server: Distinguished Name (DN) - A login on the LDAP server to which the search appliance connects to send authentication requests. If the LDAP server supports anonymous binds (authentication requests), the site does not need to specify a DN. Password (optional) - The password for the DN. Click Continue. The search appliance attempts to auto-detect the settings of the LDAP Search Base, the User Search Filter, the Group Search Filter, the Returned group format, and if SSL Support exists and displays what it has detected. The advanced settings appear. If the LDAP server is used to authenticate administrators to the search appliance, specify the LDAP groups against which they will be authenticated: Superuser Group - Any member of this group is considered an Admin Console administrator. Manager Group - Any member of this group is considered an Admin Console manager. An example of a superuser group name is "GSAAdmins" and an example of a manager group name is "GSAManagers." As shown in these examples, do not specify the entire DN in group names. Test the LDAP server settings for a potential search user by entering the following information in the LDAP Search User Authentication Test box and clicking Test LDAP Settings: Username - The user name that enables the search appliance to connect to the LDAP server (relative to the search base). Password - The password the user name that enables the search appliance to connect to the LDAP server. Configuring one or more LDAP servers on a search appliance. Editing an LDAP server configuration. Deleting an LDAP server configuration. Notes: Configure LDAP server if possible. LDAP (Lightweight Directory Access Protocol) is used to authenticate users before returning secure search results. When a user connects to the Google Search Appliance and requests a search for secure results, the search appliance asks for credentials from the user. These credentials are then forwarded to the LDAP server for validation. The user can use either LDAP or Kerberos, but not both.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-000040
- Version
- GSAP-00-000135
- Vuln IDs
-
- V-60719
- Rule IDs
-
- SV-75171r1_rule
Checks: C-61665r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Log on to the GSA Admin Console. Select "Administration". Select "User Accounts". If there are appropriate "manager" and "admin" accounts per site specific organizational requirement guidance, this is not a finding.
Fix: F-66399r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Log on to the GSA Admin Console. Select "Administration". Select "User Accounts". Create the appropriate "manager" and "admin" accounts per site specific organizational requirement guidance.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- GSAP-00-000140
- Vuln IDs
-
- V-60721
- Rule IDs
-
- SV-75173r1_rule
Checks: C-61667r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66401r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-001452
- Version
- GSAP-00-000145
- Vuln IDs
-
- V-60723
- Rule IDs
-
- SV-75175r1_rule
Checks: C-61669r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66403r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000047
- Version
- GSAP-00-000150
- Vuln IDs
-
- V-60725
- Rule IDs
-
- SV-75177r1_rule
Checks: C-61671r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66405r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- GSAP-00-000155
- Vuln IDs
-
- V-60727
- Rule IDs
-
- SV-75179r1_rule
Checks: C-61673r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Login Terms". If "Enable Login Terms Banner" is checked, this is not a finding.
Fix: F-66407r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Login Terms". Enable option "Enable Login Terms Banner". Enter banner information. Click Save. Notes: DoD Login Banners: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests- -not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. OR I've read & consent to terms in IS user agreem't.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000050
- Version
- GSAP-00-000160
- Vuln IDs
-
- V-60729
- Rule IDs
-
- SV-75181r1_rule
Checks: C-61675r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Login Terms". If "Enable Login Terms Banner" is checked, this is not a finding.
Fix: F-66409r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Login Terms". Enable option "Enable Login Terms Banner". Enter banner information. Click Save. Notes: DoD Login Banners: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests- -not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-001384
- Version
- GSAP-00-000165
- Vuln IDs
-
- V-60731
- Rule IDs
-
- SV-75183r1_rule
Checks: C-61677r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Login Terms". If "Enable Login Terms Banner" is checked, this is not a finding.
Fix: F-66411r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Login Terms". Enable option "Enable Login Terms Banner". Enter banner information. Click Save. Notes: DoD Login Banners: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests- -not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. OR I've read & consent to terms in IS user agreem't.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000136
- Version
- GSAP-00-000265
- Vuln IDs
-
- V-60733
- Rule IDs
-
- SV-75185r1_rule
Checks: C-61679r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". If a valid Syslog server is entered, this is not a finding.
Fix: F-66413r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". Enter a valid Syslog server information. Click Save. Notes: Centralized logging provides the search appliance logs user search queries. If the Syslog Server value is set, the search appliance sends the log messages to the syslog server every five minutes, assigning the messages the priority "Informational." If there weren't any new searches between the previous run and the new run, the search appliance doesn't send anything to the syslog server.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000144
- Version
- GSAP-00-000275
- Vuln IDs
-
- V-60747
- Rule IDs
-
- SV-75199r1_rule
Checks: C-61681r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If only valid emails addresses are entered, this is not a finding.
Fix: F-66427r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Enter valid email addresses that the audit failures need to be sent to be reviewed.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- GSAP-00-000280
- Vuln IDs
-
- V-60749
- Rule IDs
-
- SV-75201r1_rule
Checks: C-61683r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If valid email addresses are entered, this is not a finding.
Fix: F-66429r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Enter valid email addresses that the audit failures need to be sent to be reviewed.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- GSAP-00-000285
- Vuln IDs
-
- V-60751
- Rule IDs
-
- SV-75203r1_rule
Checks: C-61685r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If valid email addresses are entered, this is not a finding.
Fix: F-66431r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Enter valid email addresses that the audit failures need to be sent to be reviewed.
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-000160
- Version
- GSAP-00-000325
- Vuln IDs
-
- V-60753
- Rule IDs
-
- SV-75205r1_rule
Checks: C-61687r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". If there are valid entries for all DNS servers, DNS suffixes, SMTP servers, NTP servers, this is not a finding.
Fix: F-66433r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". Ensure that valid entries for all DNS servers, DNS suffixes, SMTP servers, NTP servers.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001348
- Version
- GSAP-00-000360
- Vuln IDs
-
- V-60767
- Rule IDs
-
- SV-75219r1_rule
Checks: C-61689r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". If the "Facility" setting is enabled, this is not a finding.
Fix: F-66447r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". Ensure that "Facility" setting is enabled. Click Save.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- GSAP-00-000455
- Vuln IDs
-
- V-60769
- Rule IDs
-
- SV-75221r1_rule
Checks: C-61691r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Log on to the GSA Admin Console. Select "Administration". Select "User Accounts". If there are individual "manager" and "admin" accounts per site specific organizational requirements, this is not a finding.
Fix: F-66449r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Log on to the GSA Admin Console. Select "Administration". Select "User Accounts". Create appropriate "manager" and "admin" accounts per site specific organizational requirement guidance.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- GSAP-00-000515
- Vuln IDs
-
- V-60771
- Rule IDs
-
- SV-75223r1_rule
Checks: C-61693r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Prevent browsers from saving user credentials on the Admin Console and Version Manager login pages" is checked, this is not a finding.
Fix: F-66451r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Prevent browsers from saving user credentials on the Admin Console and Version Manager login pages". Click Save.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- GSAP-00-000525
- Vuln IDs
-
- V-60773
- Rule IDs
-
- SV-75225r1_rule
Checks: C-61695r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66453r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- GSAP-00-000535
- Vuln IDs
-
- V-60775
- Rule IDs
-
- SV-75227r1_rule
Checks: C-61697r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66455r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000193
- Version
- GSAP-00-000540
- Vuln IDs
-
- V-60777
- Rule IDs
-
- SV-75229r1_rule
Checks: C-61699r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66457r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000194
- Version
- GSAP-00-000545
- Vuln IDs
-
- V-60779
- Rule IDs
-
- SV-75231r1_rule
Checks: C-61701r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66459r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-001619
- Version
- GSAP-00-000550
- Vuln IDs
-
- V-60783
- Rule IDs
-
- SV-75235r1_rule
Checks: C-61707r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66465r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- GSAP-00-000565
- Vuln IDs
-
- V-60785
- Rule IDs
-
- SV-75237r1_rule
Checks: C-61709r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "SSL Settings". Under "Other Settings" - If "Use HTTPS when serving both public and secure results" is checked, this is not a finding.
Fix: F-66467r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "SSL Settings". Under "Other Settings" - Enable option "Use HTTPS when serving both public and secure results". Click Save.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000198
- Version
- GSAP-00-000570
- Vuln IDs
-
- V-60787
- Rule IDs
-
- SV-75239r1_rule
Checks: C-61711r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - If "Use strict password checking" is checked, this is not a finding.
Fix: F-66469r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "User Accounts". Under "Other Settings" - Enable option "Use strict password checking". Click Save.
- RMF Control
- SI-6
- Severity
- M
- CCI
- CCI-001674
- Version
- GSAP-00-000660
- Vuln IDs
-
- V-60789
- Rule IDs
-
- SV-75241r1_rule
Checks: C-61713r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". Ensure that a valid Syslog server is entered correctly. If events are sent and recorded on the Syslog server, this is not a finding.
Fix: F-66471r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". Enter a valid Syslog server. Ensure that events are sent and recorded on the Syslog server.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001184
- Version
- GSAP-00-000745
- Vuln IDs
-
- V-60791
- Rule IDs
-
- SV-75243r1_rule
Checks: C-61715r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "SSL Settings". If "Enable Server Certificate Authentication" is checked, this is not a finding.
Fix: F-66473r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "SSL Settings". Enable the option "Enable Server Certificate Authentication".
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-001274
- Version
- GSAP-00-000820
- Vuln IDs
-
- V-60793
- Rule IDs
-
- SV-75245r1_rule
Checks: C-61717r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If "Enable Daily Status Email Messages" is checked and a valid administrator email address is entered, this is not a finding.
Fix: F-66475r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Select "Enable Daily Status Email Messages" and enter a valid administrator email address.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001131
- Version
- GSAP-00-000910
- Vuln IDs
-
- V-60795
- Rule IDs
-
- SV-75247r1_rule
Checks: C-61719r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "SSL Settings". Under "Other Settings" - If "Use HTTPS when serving both public and secure results" is checked, this is not a finding.
Fix: F-66477r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "SSL Settings". Under "Other Settings" - Select "Use HTTPS when serving both public and secure results".
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001683
- Version
- GSAP-00-001025
- Vuln IDs
-
- V-60797
- Rule IDs
-
- SV-75249r1_rule
Checks: C-61721r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If "Enable Daily Status Email Messages" is checked and a valid administrator email address is entered, this is not a finding.
Fix: F-66479r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Select "Enable Daily Status Email Messages" and enter a valid administrator email address.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001684
- Version
- GSAP-00-001030
- Vuln IDs
-
- V-60799
- Rule IDs
-
- SV-75251r1_rule
Checks: C-61723r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If "Enable Daily Status Email Messages" is checked and a valid administrator email address is entered, this is not a finding.
Fix: F-66481r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Select "Enable Daily Status Email Messages" and enter a valid administrator email address.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001685
- Version
- GSAP-00-001035
- Vuln IDs
-
- V-60801
- Rule IDs
-
- SV-75253r1_rule
Checks: C-61725r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If "Enable Daily Status Email Messages" is checked and a valid administrator email address is entered, this is not a finding.
Fix: F-66483r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Select "Enable Daily Status Email Messages" and enter a valid administrator email address.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001686
- Version
- GSAP-00-001040
- Vuln IDs
-
- V-60803
- Rule IDs
-
- SV-75255r1_rule
Checks: C-61727r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". If "Enable Daily Status Email Messages" is checked and a valid administrator email address is entered, this is not a finding.
Fix: F-66485r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "System Settings". Select "Enable Daily Status Email Messages" and enter a valid administrator email address.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GSAP-00-001045
- Vuln IDs
-
- V-60805
- Rule IDs
-
- SV-75257r1_rule
Checks: C-61729r1_chk
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". In the "Static Routes" field, ensure the required static routes are entered with one route per line. If proper destination host or network IP address, netmask, and destination gateway for a particular static route are entered, this is not a finding.
Fix: F-66487r1_fix
Open the GSA Web Admin Console at https:<your GSA IP or hostname>:8443. Login to the GSA management interface. Navigate to "Administration", select "Network Settings". In the "Static Routes" field, ensure the required static routes are entered with one route per line. Ensure that the destination host or network IP address, netmask, and destination gateway for a particular static route are entered on one line with a space between each part of the route. Click Update Setting and Perform Diagnostics.