Ivanti Policy Secure NDM Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- IVPS-NM-000006
- Vuln IDs
-
- V-284518
- Rule IDs
-
- SV-284518r1244923_rule
Checks: C-89083r1244596_chk
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. Under the section "Account Lockout", verify "Enable Account Lockout for users" is checked. 3. Verify "Maximum wrong password attempts" is set to "3". 4. Verify "Account Lockout Period in Minutes" is set to "15". If account lockout is not configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes, this is a finding.
Fix: F-88988r1244186_fix
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. Under the section "Account Lockout", check the box for "Enable Account Lockout for users". 3. Under the section "Account Lockout" set "Maximum wrong password attempts" to "3". 4. Under the section "Account Lockout" set "Account Lockout Period in Minutes" to "15". 5. Click "Save Changes".
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- IVPS-NM-000007
- Vuln IDs
-
- V-284519
- Rule IDs
-
- SV-284519r1244925_rule
Checks: C-89084r1244924_chk
Determine if the DoW-approved banner is presented before accessing Policy Secure. 1. In the Web UI, navigate to Authentication >> Signing In >> Sign-In Policies. 2. Click "*/admin/" (or the custom URL used for common access card [CAC]/public key access [PKI] token admin access). Under "Configure Sign In Notifications" if the "Pre-Auth Sign-in Notification" is not checked, or if the previously mentioned notification text is not assigned to this policy, this is a finding.
Fix: F-88989r1244647_fix
1. In the Web UI, navigate to Authentication >> Signing In >> Sign-In Notifications. 2. Click "New Notification". 3. For name, type: "DOD Notice and Consent". 4. In the text box, enter the following: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests -- not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. 5. Click "Save Changes". 6. Go to Authentication >> Signing In >> Sign-In Policies. 7. Click the "*/admin/" (or the custom URL used for CAC/PKI token admin access). 8. Under "Configure Sign In Notifications", check the box for "Pre-Auth Sign-in Notification" and in the drop-down menu, assign the notification titled "DOD Notice and Consent". 9. Repeat steps 7 and 8 for each role or URL. Note: If the Use the Sign-in Notification associated to the assigned role is enabled, complete the implementation by selecting the sign-in notification on the Users >> User Roles >> Role Name >> General >> UI Options page or Administrators >> Admin Roles >> Role Name >> General >> UI Options page.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- IVPS-NM-000011
- Vuln IDs
-
- V-284520
- Rule IDs
-
- SV-284520r1244926_rule
Checks: C-89085r1244191_chk
In the Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings. Under the "Select Events to Log" section, if "Detailed Log Note" is not checked, this is a finding.
Fix: F-88990r1244192_fix
1. In the Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings. 2. Under the "Select Events to Log" section, check the box for "Detailed Log Note". 3. Click "Save Changes".
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-000159
- Version
- IVPS-NM-000018
- Vuln IDs
-
- V-284521
- Rule IDs
-
- SV-284521r1244927_rule
Checks: C-89086r1244194_chk
1. In the Web UI, navigate to System >> Status >> Dashboard. 2. Click the "Overview" tab. 3. Under "Appliance Details" and "System Date and Time", select "Edit". If the "Time Zone" is not set to "(GMT) Coordinated Universal Time" this is a finding.
Fix: F-88991r1244195_fix
1. In the Web UI, navigate to System >> Status >> Dashboard. 2. Click the "Overview" tab. 3. Under "Appliance Details" and "System Date and Time", select "Edit". 4. Select "(GMT) Coordinated Universal Time". 5. Click "Save Changes".
- RMF Control
- CM-5
- Severity
- H
- CCI
- CCI-001499
- Version
- IVPS-NM-000024
- Vuln IDs
-
- V-284522
- Rule IDs
-
- SV-284522r1244928_rule
Checks: C-89087r1244197_chk
1. In the Ivanti Policy Secure Web UI, navigate to Administrators >> Admin Realms >> Admin Realms. 2. Click the admin realm that is currently being used on the Policy Secure for CAC/PKI token administrator logins. 3. View the "Role Mapping" tab. If there are not two group definitions to Role Assignments for Admin and Read-Only, this is a finding.
Fix: F-88992r1244649_fix
Configure the admin realm that is currently being used on the Policy Secure for CAC/PKI token administrator logins. 1. In the Ivanti Policy Secure Web UI, navigate to Administrators >> Admin Realms >> Admin Realms. 2. Select the admin realm that is currently being used on the Policy Secure for CAC/PKI token administrator logins. 3. Click "Role Mappings". 4. Click "New Rule". 5. Click "Rule Based" on Group Membership". 6. Click "Update". 7. Type a name for the admin group. 8. Under available groups, select the LDAP group for admins (e.g., "ivanti.admins.gsg"). If no groups currently exist in the window, click "Groups" and add the group from the LDAP directory window that pops up. 9. Under "Available Roles", select ".Administrators". 10. Click "Save Changes". 11. Click "New Rule". 12. Click "Rule Based" on "Group Membership". 13. Click "Update". 14. Type a name for the read-only group. 15. Under available groups, select the LDAP group for nonadmins (e.g., "ivanti.ROadmin.gsg"). If no groups currently exist in the window, click "Groups" and add the group from the LDAP directory window that pops up. 16. Under "Available Roles", select ".Read-Only Administrators". 17. Click "Save Changes".
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001358
- Version
- IVPS-NM-000026
- Vuln IDs
-
- V-284523
- Rule IDs
-
- SV-284523r1244929_rule
Checks: C-89088r1244200_chk
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. Select the "Users" tab and review the user list. If more than one local user exists, this is a finding.
Fix: F-88993r1244600_fix
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. Click the "Users" tab. 3. Create the emergency local user or click the default admin user. 4. Click "Enabled". 5. Click "Allow Console Access". 6. Click "Save Changes".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- IVPS-NM-000029
- Vuln IDs
-
- V-284524
- Rule IDs
-
- SV-284524r1244930_rule
Checks: C-89089r1244203_chk
In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. If the minimum length is not 15 characters, this is a finding.
Fix: F-88994r1244204_fix
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. For minimum length, enter "15". 3. Click "Save Changes".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- IVPS-NM-000030
- Vuln IDs
-
- V-284525
- Rule IDs
-
- SV-284525r1244994_rule
Checks: C-89090r1244206_chk
In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. If "Password must have mix of UPPERCASE and lowercase letters" is not checked or "Password must have at least __ letters" is not set to "1" or more, this is a finding.
Fix: F-88995r1244207_fix
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. Select "Password must have at least __ letters". 3. In the box enter "1" or more. 4. Check the box for "Password must have mix of UPPERCASE and lowercase letters". 5. Click "Save Changes".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- IVPS-NM-000032
- Vuln IDs
-
- V-284526
- Rule IDs
-
- SV-284526r1244932_rule
Checks: C-89091r1244209_chk
In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. If the value for the setting for "Password must have at least __ digits" is not "1" or more, this is a finding.
Fix: F-88996r1244210_fix
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. Check the box for "Password must have at least __ digits". 3. In the box, enter "1". 4. Click "Save Changes".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- IVPS-NM-000033
- Vuln IDs
-
- V-284527
- Rule IDs
-
- SV-284527r1244933_rule
Checks: C-89092r1244212_chk
In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. If the value for "Password must have at least __ Special Characters" is not set to "1" or more, this is a finding.
Fix: F-88997r1244213_fix
1. Check the box for "Password must have at least __ Special Characters". 2. In the box, enter "1" or more. 3. Click "Save Changes".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- IVPS-NM-000034
- Vuln IDs
-
- V-284528
- Rule IDs
-
- SV-284528r1244934_rule
Checks: C-89093r1244215_chk
In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. If the setting for "new password must differ from the previous password position" and the value of "new password must differ from the previous password position" is not set to "8", this is a finding.
Fix: F-88998r1244602_fix
1. In the Web UI, navigate to Authentication >> Auth Servers >> Administrators. 2. Check the box for "new password must differ from the previous password position". 3. In the box, enter "8" or more. 4. Click "Save Changes".
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000197
- Version
- IVPS-NM-000035
- Vuln IDs
-
- V-284529
- Rule IDs
-
- SV-284529r1244935_rule
Checks: C-89094r1244218_chk
1. In the Web UI, navigate to System >> Configuration >> Inbound SSL Options. 2. Under "Allowed SSL and TLS Version", verify "Accept only TLS 1.2 (maximize security)" is selected. 3. Navigate to System >> Configuration >> Outbound SSL Options. 4. View the setting for "Allowed SSL and TLS Version". If "Accept only TLS 1.2 (maximize security)" is not checked, this is a finding.
Fix: F-88999r1244219_fix
1. In the Web UI, navigate to System >> Configuration >> Inbound SSL Options. 2. Under "Allowed SSL and TLS Version", check the box for "Accept only TLS 1.2 (maximize security)". 3. Click "Save Changes". 4. Click "Proceed" to accept the cipher change. 5. Navigate to System >> Configuration >> Outbound SSL Options. 6. Under "Allowed SSL and TLS Version", check the box for "Accept only TLS 1.2 (maximize security)". 7. Click "Save Changes". 8. Click "Proceed" to accept the cipher change.
- RMF Control
- SC-10
- Severity
- H
- CCI
- CCI-001133
- Version
- IVPS-NM-000037
- Vuln IDs
-
- V-284530
- Rule IDs
-
- SV-284530r1244936_rule
Checks: C-89095r1244221_chk
1. In the Web UI, navigate to Administrators >> Admins Role >> Delegated Admin Roles. 2. Click the configured admin role being used for CAC/PKI token admin logins, by default it is ".Administrators". 3. Click the "Session Options" tab. 4. View the "Session Lifetime" section. If the idle timeout is not set to "10", this is a finding.
Fix: F-89000r1244222_fix
1. In the Web UI, navigate to Administrators >> Admins Role >> Delegated Admin Roles. 2. Click the configured admin role being used for CAC/PKI token admin logins, by default it is ".Administrators". 3. Click the "Session Options" tab. 4. In the "Session Lifetime" section, set the Idle Timeout to "10". 5. Click "Save Changes".
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- IVPS-NM-000042
- Vuln IDs
-
- V-284531
- Rule IDs
-
- SV-284531r1244937_rule
Checks: C-89096r1244728_chk
Verify realms and roles are configured as needed to meet mission requirements. 1. In the Web UI, navigate to Administrators >> Admin Realms >> Admin Realms. 2. Click the admin realm that is currently being used on the Policy Secure for administrator logins. By default, it is "Admin Users". 3. In the "General" tab, under Servers >> Directory/Attribute, verify "none" are listed. 4. In the "Role Mapping" tab, under "when users meet these conditions" set the following: - "Group" must be used, and the local site's administrator active directory group must be selected and assigned to the ".Administrators" role. Note: This role could be different if using something other than the default ".Administrators" role. If a realm or role mapping is not configured to prevent nonprivileged users from executing privileged functions, this is a finding.
Fix: F-89001r1244729_fix
Configure realms and roles as needed to meet mission requirements. The ".Administrators" role is a default role name, but other administrator role names can be used. Groups must be used; separate usernames or an allow-all username of * is not acceptable. 1. In the Web UI, navigate to Administrators >> Admin Realms >> Admin Realms. 2. Click the admin realm that is used on the Policy Secure for administrator logins. By default, it is "Admin Users". 3. In the "General" tab, under Servers >> Directory/Attribute, select the previously configured LDAP Directory. If none are configured, follow vendor supplied instructions for creating an LDAP Authentication Server. 4. In the "Role Mapping" tab, under "when users meet these conditions" select "New rule". 5. Under "Rule based on", select "Group Membership". 6. Name the rule. 7. Select "is". 8. Provide the exact group name in the text box. This name must match the "CN=" attribute name. For example, if the group is "CN=ivanti.adm.group" then add the "ivanti.adm.group" to the text box. 9. Under "then assign these roles", select the admin role used by Policy Secure for admin logins. By default, this is the ".Administrators". 10. Click "Save Changes". 11. Under "Role Mapping" if there are more roles needed for more specific role-based access to the Policy Secure, configure more of them here. 12. Click "Save Changes".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- IVPS-NM-000048
- Vuln IDs
-
- V-284532
- Rule IDs
-
- SV-284532r1244938_rule
Checks: C-89097r1244767_chk
If SNMP is not used, this is not applicable. 1. In the Web UI, navigate to System >> Log/Monitoring >> SNMP. 2. Under "SNMP version data", verify v2c is not selected. If any version other than v3 is selected, this is a finding.
Fix: F-89002r1244228_fix
1. In the Web UI, navigate to System >> Log/Monitoring >> SNMP. 2. Under "SNMP version data", select "v3". 3. Under "Agent Properties", select SNMP Queries. 4. Define the System Name. 5. Define the System Location. 6. Define the System Contact. 7. Under "SNMPv3 Configuration" and "User 1", type the username. 8. Select the "Security Level" of Auth, Priv. 9. Select "SHA" as the Auth Protocol. 10. Type the Auth password. 11. Select "CFB-AES-128" as the Priv Protocol. 12. Type the Priv password. 13. Under "Optional Traps", select "Critical" and "Major" log events. 14. Click "Save changes".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- IVPS-NM-000049
- Vuln IDs
-
- V-284533
- Rule IDs
-
- SV-284533r1244995_rule
Checks: C-89098r1244939_chk
1. In the Web UI, navigate to System >> Status >> Dashboard. 2. Click the "Overview" tab. 3. Under "Appliance Details" and "System Date and Time", select "Edit". 4. Verify "Use Pool of NTP servers" is checked. 5. Verify at least two NTP servers are configured. 6. Verify a key is configured. If Policy Secure is not configured to use redundant NTP services that is hosted by a trusted source or a DoW-compliant enterprise or local NTP server, this is a finding.
Fix: F-89003r1244732_fix
1. In the Web UI, navigate to System >> Status >> Dashboard. 2. Click the "Overview" tab. 3. Under "Appliance Details" and "System Date and Time", select "Edit". 4. Select "(GMT) Coordinated Universal Time". 5. Select "Use Pool of NTP servers". 6. Enter the IP/hostname of each NTP server in the "NTP Server 1", "NTP Server 2", etc. 7. Under the key section, input the key in the following format: <keynumber> <algorithm> <key>. Note: There must be a space between each section of <keynumber> <algorithm> <key>. 8. Click "Save changes".
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-002890
- Version
- IVPS-NM-000052
- Vuln IDs
-
- V-284534
- Rule IDs
-
- SV-284534r1244941_rule
Checks: C-89099r1244734_chk
1. In the Web UI, navigate to System >> Configuration >> Advanced Networking. 2. Verify the management interface is selected for NTP, SNMP, Syslog and Log Archiving. 1. In the Web UI, navigate to Administrators >> Admin Realms. 2. Click each Admin Authentication Realm. 3. Click on Authentication policy for each realm. 4. Verify the "Enable to sign in" check box is not checked for "Management Port". If the device is not configured to connect to the management port for NTP, SNMP, and Syslog and Log Archiving communications, this is a finding.
Fix: F-89004r1244735_fix
Enable and configure alternative protocols and the admins to login to the Management port as well as the default URL port. 1. In the Web UI, navigate to Network >> Management >> Settings. 2. Check the box for "Use Port" to enable. 3. Add an IPv4 Address, Netmask, and GW. 4. Check the box to enable IPv6. 5. Add an IP Address, Prefix, and GW. 1. In the Web UI, navigate to System >> Configuration >> Advanced Networking. 2. Select the management interface for NTP, SNMP, Syslog & Log Archive (this should be selected by default). 3. Click "Save". 1. In the Web UI, navigate to Administrators >> Admin Realms. 2. Click each Admin Authentication Realm. 3. Click on Authentication policy. 4. Select each realm and select "Enable administrators to sign in on the Management port". This should be the only port checked.
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-003123
- Version
- IVPS-NM-000053
- Vuln IDs
-
- V-284535
- Rule IDs
-
- SV-284535r1244943_rule
Checks: C-89100r1244656_chk
1. In the Web UI, navigate to System >> Configuration >> Security >> Inbound SSL Options. 2. Verify the "Turn on JITC mode" checkbox is not checked. 3. Verify the "Turn on NDcPP mode" checkbox is not checked. 4. Verify the "Turn on FIPS mode" checkbox is not checked. If JITC and NDcPP compliance modes are not configured, this is a finding.
Fix: F-89005r1244942_fix
1. In the Web UI, navigate to System >> Configuration >> Security >> Inbound SSL Options. 2. Under the DoW Certification option, enable "Turn on JITC mode" to enable the JITC mode security features. 3. Under SSL NDcPP Mode Option, enable "Turn on NDcPP mode" to enable the NDcPP mode security features. 4. Under SSL FIPS Mode Option, check enable "Turn on FIPS mode" to enable the FIPS mode security features. 5. Click "Save changes" and confirm after the web UI asks for SSL cipher configuration changes.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- IVPS-NM-000115
- Vuln IDs
-
- V-284536
- Rule IDs
-
- SV-284536r1244945_rule
Checks: C-89101r1244239_chk
1. In the Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings. 2. Verify "Select Events to Log" is configured to log all items. 3. Verify "Syslog Servers" is configured with a remote syslog server name/IP address. 4. Verify TSL is selected. If user access events log audit records are not configured to be sent to a remote centralized syslog server, this is a finding.
Fix: F-89006r1244944_fix
1. In the Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings. 2. Under "Select Events to Log", check all items. 3. Under "syslog Servers" add an IP address/server name/IP. 4. Set the facility to LOCAL0. 5. Set type to TLS. 6. Optionally, only if a client certificate is required for the syslog server, select the client certificate to use for the syslog traffic. If none exists, import the DoW-signed client key pair to the Policy Secure under System >> Configuration >> Certificates >> Client Auth Certificates. 7. Set the standard filer. 8. Set the source interface as either the management or internal interface. 9. Click "Add". 10. Click "Save Changes".
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- IVPS-NM-000056
- Vuln IDs
-
- V-284537
- Rule IDs
-
- SV-284537r1244947_rule
Checks: C-89102r1244658_chk
1. In the Web UI, navigate to System >> Log/Monitoring >> Events >> Settings. 2. Verify "Select Events to Log" is configured to log all items. 3. Verify "Syslog Servers" is configured with a remote syslog server name/IP address. 4. Verify "TSL" is selected. If events access log audit records are not configured to be sent to a remote centralized syslog server, this is a finding.
Fix: F-89007r1244946_fix
1. In the Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings. 2. Under "Select Events to Log", check all items. 3. Under "syslog Servers" add an IP address/server name/IP. 4. Set the facility to "LOCAL0". 5. Set type to "TLS". 6. Optionally, if only a client certificate is required for the syslog server, select the client certificate to use for the syslog traffic. If none exists, import the DoW-signed client key pair to the Policy Secure under System >> Configuration >> Certificates >> Client Auth Certificates. 7. Set the standard filer. 8. Set the source interface as either the management or internal interface. 9. Click "Add". 10. Click "Save Changes".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000370
- Version
- IVPS-NM-000058
- Vuln IDs
-
- V-284538
- Rule IDs
-
- SV-284538r1244948_rule
Checks: C-89103r1244737_chk
1. In the Web UI, navigate to Authentication >> Auth Servers >> Authentication/Authorization Servers. 2. Select the directory service connector that was created. 3. Check to ensure a primary and backup server is configured. If a primary and backup connection is not configured, this is a finding.
Fix: F-89008r1244738_fix
Configure at least two authentication servers. 1. In the Web UI, navigate to Administrators >> Auth Servers. 2. Click "New Servers", under "Server type", select "Certificate Server", then click "New Server". 3. Type a Name, then under "User Name template", type: <certAttr.altname.UPN>. 4. Click "Save changes". 5. Navigate to Administrators >> Auth Servers. 6. Click "New Servers", under "Server type", select "LDAP Server", then click "New Server". 7. Type a name for the primary LDAP server domain. 8. LDAP server: the FQDN of the server (an IP address may cause an error as the LDAP server certificate might not have an IP in the SAN field). 9. LDAP port: 636. 10. Backup LDAP Server1: the FQDN of the secondary server (an IP address may cause an error as the LDAP server certificate might not have an IP in the SAN field). 11. Backup LDAP Port1: 636. 12. If a third LDAP server is needed, add this and the port info under Backup LDAP Server2 and Backup LDAP Port2. 13. LDAP Server Type: Active Directory. 14. Connection: LDAPS. 15. Ensure "Validate Server Certificate" is checked. 16. Connection Timeout: 15. 17. Search Timeout: 60. 18. Scroll down to the bottom and click "Save changes", then click "Test Settings" to ensure valid communications are possible. Note: If there are failures in this testing, ensure the step for Device Certificates and Trusted Server CAs were completed. If not, this will cause LDAPS certificate issues. 19. Under "authentication required", click the box for "Authentication required to search LDAP". 20. Enter the service account's Admin DN using this as an example format: CN=PCS.SVC,OU=IVANTI,DC=dod,DC=mil. 21. Enter the service account's password. 22. Under "Finding user entries", add the base DN of the domain using this as an example format: DC=dod,DC=mil. 23. Under "filter", use this specific attribute configuration: userPrincipalName=<USER>. 24. Under "group membership", add the base DN where admin users will access, using this as an example format: OU=IVANTI,DC=dod,DC=mil. 25. Under "filter", use the following: cn=<GROUPNAME>. 26. Under "member attribute", use the following: member. 27. Click "Save Changes". 28. At the LDAP server configuration screen, scroll down and click the "Server Catalog" hyperlink. 29. Under attributes, click "New", type "userPrincipalName", then click "Save Changes". 30. Under groups, click "Search". In the search box, type the group name used for admin logins. 31. Check the box next to the group that is found and click "Add Selected". 32. Repeat these steps for all various groups needed for various roles on the Policy Secure system. For example, groups for auditors, ISSOs, NOC, SOC, Viewer, etc. 33. Click "Save Changes".
- RMF Control
- CP-9
- Severity
- M
- CCI
- CCI-000537
- Version
- IVPS-NM-000059
- Vuln IDs
-
- V-284539
- Rule IDs
-
- SV-284539r1244949_rule
Checks: C-89104r1244248_chk
1. In the Ivanti Policy Secure Web UI, navigate to Maintenance >> Archiving >> Archive Servers. 2. Review the archive schedule to verify the configuration is configured to backup weekly, at a minimum. 3. Review the backup log to verify the backup is kicked off manually when system configuration occurs. If backups of system level information are not scheduled for at least weekly, this is a finding.
Fix: F-89009r1244249_fix
1. In the Ivanti Policy Secure Web UI, navigate to Maintenance >> Archiving >> Archive Servers. 2. Click "SCP" if using an SFTP/SCP server, other mechanisms may not be allowed due to local security policy. Check with the information system security manager (ISSM) before configuring anything other than SCP. 3. Under "Archive Server", type the host name or IPv4/IPv6 address. 4. In "Destination Directory", type the path of the backup (e.g., "/backupfolder/ics/"). 5. In the "Username" field, type the username with SCP/SFTP permissions on the backup server. 6. In the "Password" field, type the password. 7. Under "Archive Schedule" select "Archive System Configuration", then click the day of the week and time when the backup should be sent. 8. Under "Archive System Configuration", ensure a password is given to encrypt the backup. 9. Under "Archive Schedule", select "Archive User Accounts", then click the day of the week and time when the backup should be sent. 10. Under "Archive User Accounts", ensure a password is given to encrypt the backup. 11. Click "Save Changes".
- RMF Control
- SC-17
- Severity
- M
- CCI
- CCI-001159
- Version
- IVPS-NM-000061
- Vuln IDs
-
- V-284540
- Rule IDs
-
- SV-284540r1244952_rule
Checks: C-89105r1244950_chk
1. In the Web UI, navigate to System >> Configuration >> Certificates >> Device Certificates. 2. View the certificate to verify it is signed by a valid DoW CA. 3. Verify the certificate is the only one present and configured for use on interfaces. If a DoW CA certificate is not used, this is a finding.
Fix: F-89010r1244951_fix
1. In the Web UI, navigate to System >> Configuration >> Certificates >> Device Certificates. 2. Click "New CSR". 3. Add a Common Name in FQDN format. 4. Add a Country code of US. 5. Under "Key type", if using RSA, select "RSA". If using ECC, select "ECC". 6. Under "Key length", if using RSA, select at least 2048. If using ECC, select "P-384". 7. Enter in random data in the text field. 8. Click "Create CSR". 9. Copy the Base 64/PEM encoded certificate request shown on the screen and paste it to a text file. Ensure the file has the file suffix of .csr. 10. Complete the local RA process for DoW web server certificate requests. Ensure that SANs are added to the certificate by the issuing CA to include the host name, cluster names, and all FQDNs. 11. Once the certificate is provided by the CA, go to System >> Configuration >> Certificates >> Device Certificates. 12. Click "Browse" and select the certificate file issued by the CA, then click "Import". 13. Click "Save Changes". 14. Click on the imported certificate. 15. On the internal port, click add for the cluster internal VIP and <Internal Port>. 16. On the external port, click add for the cluster external VIP and <External Port>. 17. Check the box for "Management Port". 18. Under "Certificate Status Checking", click the box for "Use CRLs". 19. Click "Save Changes".
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- IVPS-NM-000062
- Vuln IDs
-
- V-284541
- Rule IDs
-
- SV-284541r1244953_rule
Checks: C-89106r1244254_chk
1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Realms. 2. Click the configured admin realm being used for CAC/PKI token admin logins. 3. Click the "Authentication Policy" tab, then click "Limits". If the "Maximum number of sessions per user" field shows any value other than "1", this is a finding.
Fix: F-89011r1244255_fix
1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Realms. 2. Click the configured admin realm being used for CAC/PKI token admin logins. 3. Click the "Authentication Policy" tab, then click "Limits". 4. In "Maximum number of sessions per user", enter "1". 5. Click "Save Changes".
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000765
- Version
- IVPS-NM-000065
- Vuln IDs
-
- V-284542
- Rule IDs
-
- SV-284542r1244955_rule
Checks: C-89107r1244954_chk
Verify the admin realm is configured for certificate authentication. 1. In the Web UI, navigate to Administrators >> Admin Realms. 2. View the configuration for the admin realm used for administrator sign-in (this is called "Admin Users" by default). 3. Authentication: View the certificate authentication server name. 4. Verify the box for "Enable dynamic policy evaluation" is checked. 5. Verify the box for "Refresh roles" and "refresh resource policies" is checked. Verify the certificate authentication server is configured to use DoW PKI. 1. Navigate to Administrators >> Auth. Servers. 2. Select Certificate from the list, then select the name of the certificate authentication server name that was used for the admin realm. 3. Verify the username template is set to <certAttr.altname.UPN>. If Ivanti Policy Secure is not configured to use DoW PKI as MFA for admin logins, this is a finding.
Fix: F-89012r1244663_fix
Create a certificate authentication server with the "Certificate" server type to handle the common access card (CAC)/PKI handshake. 1. In the Web UI, navigate to Administrators >> Auth. Servers. 2. Select "Certificate" from the list and click "New Server". 3. Enter a name. 4. Under "User Name Template", type <certAttr.altname.UPN>. 5. Click "Save Changes". Configure the Admin Realm to tie the certificate authentication and the LDAP lookup together. 1. Navigate to Administrators >> Admin Realms. 2. Click the admin realm being used. "Admin Users" is defined by default. 3. Authentication: Select the certificate authentication server created previously that included the User Name Template <certAttr.altname.UPN>. 4. Directory/Attribute: Select the LDAP server with the admin accounts. 5. Check the box for "Enable dynamic policy evaluation". 6. Check both "Refresh roles" and "Refresh resource policies". 7. Click "Save Changes". Note: Role Mappings: Created rules that map users to the "Administrator" role based on LDAP groups. Update the Admin Sign-in Policy by configuring the admin sign-in URL to use this realm. 1. In the Web UI, navigate to Authentication >> Signing In >> Sign-in Policies. 2. Create a new URL or edit the "*/admin/" URL, depending on the site. Note: It is recommended to create a new sign-in URL until this configuration is fully tested to ensure there is still web UI reachability in the troubleshooting process. 3. Under "Authentication Realm", click the "User picks from a list of authentication realms". 4. Click "Save Changes".
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000185
- Version
- IVPS-NM-000066
- Vuln IDs
-
- V-284543
- Rule IDs
-
- SV-284543r1244956_rule
Checks: C-89108r1244787_chk
1. In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs. 2. Click each DoW client CA. 3. Verify that under "Client certificate status checking", "OCSP", "CRL", or both are checked. Example: "Use OCSP with CRL fallback" is selected under the "Client certificate status checking" setting. If the ICS is not configured to use DoW approved OCSP responders and/or CRLs to validate certificates used for PKI-based authentication, this is a finding.
Fix: F-89013r1244788_fix
1. In the ICS Web UI, navigate to System >> Configuration >> Certificates >> Trusted Client CAs. 2. Click the first DoW client CA. 3. If OCSP only is used, under "Client certificate status checking", select "Use OCSP". 4. If CRL is used, under "Client certificate status checking", select "Use CRL" option. Note: The recommended option is "Use OCSP with CRL fallback" option under "Client certificate status checking". 5. Repeat these steps for every other client certificate CA.
- RMF Control
- Severity
- M
- CCI
- CCI-004192
- Version
- IVPS-NM-000073
- Vuln IDs
-
- V-284544
- Rule IDs
-
- SV-284544r1244957_rule
Checks: C-89109r1244263_chk
1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Users >> Authentication Policy. 2. Click the configured admin realm being used for common access card (CAC)/public key infrastructure (PKI) token admin logins. 3. Click the "Authentication Policy" tab, then click "Source IP". In "Administrator Sign in Port" if there are any ports selected for "Administrator Sign in" other than "Management Port", this is a finding.
Fix: F-89014r1244665_fix
1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Users >> Authentication Policy. 2. Click the configured admin realm used for CAC/PKI token admin logins. 3. Click the "Authentication Policy" tab, then click "Source IP". 4. In "Administrator Sign in Port" under Administrator Sign in Ports Select only the "Management Port".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002234
- Version
- IVPS-NM-000096
- Vuln IDs
-
- V-284545
- Rule IDs
-
- SV-284545r1244958_rule
Checks: C-89110r1244266_chk
In the Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings. Under the section "Select Events to Log", if "Administrator changes" is not checked, this is a finding.
Fix: F-89015r1244613_fix
1. In the Web UI, navigate to Administrators >> Admin Realms >> Admin Realms. 2. Check the box for "Administrator changes" under the section "Select Events to Log". 3. Click "Save Changes".
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- IVPS-NM-000110
- Vuln IDs
-
- V-284546
- Rule IDs
-
- SV-284546r1244959_rule
Checks: C-89111r1244269_chk
1. Check the vendor portal to obtain the version and release dates for the latest releases. 2. Navigate to Maintenance >> System >> Platform to inspect the version number of the installed release. If software updates are not being installed within 30 days from publication, this is a finding.
Fix: F-89016r1244769_fix
Regularly log in to the Ivanti Success Portal to check for new maintenance releases. Back Up Configuration (Pre-Update): 1. Navigate to Maintenance >> Archiving >> Configuration Archive. 2. Select "Save Config As..." and download the binary configuration file. 3. Export User and Admin local databases separately if there are a large number of local accounts. 4. Download and verify the image. 5. Download the appropriate .pkg or system image from Ivanti. 6. Run a SHA-256 checksum on the downloaded file and compare it against the hash provided on the Ivanti download page. Install the Update: 1. Go to Maintenance >> System >> Upgrade. 2. Under "Upload and Install System Software", click "Browse" and select the verified update file. 3. Click "Install". The appliance will automatically reboot. Note: Log the date of the update to show it was completed within the mandated 30-day window.
- RMF Control
- SA-22
- Severity
- H
- CCI
- CCI-003376
- Version
- IVPS-NM-000113
- Vuln IDs
-
- V-284547
- Rule IDs
-
- SV-284547r1244960_rule
Checks: C-89112r1244272_chk
Check the software version installed against the vendor supported version. 1. Navigate to the System Status page from other admin console pages by selecting System >> Status. 2. Click the "System Version Download Package" link to download the software version running on the system. If the software version is not a version supported by the vendor, this is a finding.
Fix: F-89017r1244273_fix
Upgrade the system software to a vendor supported version. 1. Select Maintenance >> System >> Upgrade/Downgrade to display the system software maintenance page. 2. Under "Install Service Package", select one of the following options to proceed: a. From "File", use the "Browse" button to locate and select the service package file. b. From "Staged Package", select the service package file that was previously uploaded. Note: Do not select the "Deletes" option when upgrading software. This option is available to support downgrading software. 3. Click "Install".
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- IVPS-NM-000116
- Vuln IDs
-
- V-284638
- Rule IDs
-
- SV-284638r1244993_rule
Checks: C-89205r1244764_chk
1. In the Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings. 2. Verify "Select Events to Log" is configured to log all items. 3. Verify "Syslog Servers" is configured with a remote syslog server name/IP address. 4. Verify TSL is selected. If admin access events log audit records are not configured to be sent to a remote centralized syslog server, this is a finding.
Fix: F-89110r1244992_fix
1. In the Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings. 2. Under "Select Events to Log", check all items. 3. Under "syslog Servers", add an IP address/server name/IP. 4. Set the facility to LOCAL0. 5. Set type to TLS. 6. (Optionally, only if a client cert is required for the syslog server) Select the client certificate to use for the syslog traffic. If none exists, import the DoW-signed client key pair to the Policy Secure under System >> Configuration >> Certificates >> Client Auth Certificates. 7. Set the standard filer. 8. Set the source interface as either the management or internal interface. 9. Click Add. 10. Click save changes.