Nutanix Acropolis Application Server Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- NXAC-AS-000001
- Vuln IDs
-
- V-279415
- Rule IDs
-
- SV-279415r1191367_rule
Checks: C-83968r1191029_chk
Verify DODIN mode is enabled to ensure maximum concurrent session is limited to 10. 1. For AOS, run the following command: $ ncli cluster get-cvm-security-config Enable DoDin Additiona... : true 2. For Prism Central, run the following command: $ ncli cluster get-pcvm-security-config Enable DoDin Additiona... : true 3. For Files, run the following command: $ ncli cluster get-afs-security-config Enable DoDin Additiona... : true If the value for "Enable DoDin Additional" is not set to "True", this is a finding.
Fix: F-83873r1191030_fix
Set max concurrent connections to 10 by running the following command: $ configure_dod_mode.sh enter_dod_mode
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002361
- Version
- NXAC-AS-000002
- Vuln IDs
-
- V-279416
- Rule IDs
-
- SV-279416r1191034_rule
Checks: C-83969r1191032_chk
Validate the Prism WebUI Session Idle timeout and Timeout Override is set to 15 minutes and Deny Override. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "UI Settings". 4. Verify the "Session Idle Timeout for current User" to 15 Minutes. 5. Verify the "Default Session Idle Timeout for Non-Admin Users" to 15 Minutes. 6. Verify the "Session Idle Override for Non-Admin Users" to "Deny Override". If the any of the idle timeout settings or override setting do not match the required settings, this is a finding.
Fix: F-83874r1191033_fix
Configure the Nutanix AOS Prism Element WebUI Session Idle timeout and Override settings. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "UI Settings". 4. Set the "Session Idle Timeout for current User" to 15 Minutes. 5. Set the "Default Session Idle Timeout for Non-Admin Users" to 15 Minutes. 6. Set the "Session Idle Override for Non-Admin Users" to "Deny Override".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- NXAC-AS-000004
- Vuln IDs
-
- V-279418
- Rule IDs
-
- SV-279418r1191040_rule
Checks: C-83971r1191038_chk
Verify the Signing Algorithm of the current TLS certificate. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "SSL Certificate". If there is no DOD TLS certificate loaded, this is a finding.
Fix: F-83876r1191039_fix
Import a DOD PKI-issued TLS certificate. 1. Click the gear icon in the upper-right corner. 2. Navigate to "SSL Certificate". 3. Select the option to import certificate and follow the prompts.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- NXAC-AS-000009
- Vuln IDs
-
- V-279421
- Rule IDs
-
- SV-279421r1192347_rule
Checks: C-83974r1192346_chk
Nutanix AOS supports user and group role mapping. Verify all users or groups match that of the documented mapping policies in the system security plan (SSP). 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Role mapping". For each user or group listed, verify the role granted is according to access control policies. If not, this is a finding.
Fix: F-83879r1191048_fix
Configure the user and group mappings to be compliant with the documented mapping policies defined by in the SSP. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Role mapping". 4. Add users and groups to role mappings per policy.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- NXAC-AS-000011
- Vuln IDs
-
- V-279422
- Rule IDs
-
- SV-279422r1191052_rule
Checks: C-83975r1191050_chk
Verify the Prism WebUI "Welcome Banner" is enabled. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the "Welcome Banner". 4. Verify the "Enable Banner" box is selected. If the "Enable Banner" box is not checked, this is a finding. Confirm the Nutanix AOS Prism WebUI is set to display the Standard Mandatory DOD Notice and Consent Banner. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the "Welcome Banner" and enter the following text exactly as presented below. You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. If the Welcome Banner is not configured with the Standard Mandatory DOD Notice and Consent Banner, this is a finding.
Fix: F-83880r1191051_fix
Configure the Nutanix AOS Prism Element WebUI to display the Standard Mandatory DOD Notice and Consent Banner. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the "Welcome Banner". 4. Set the Welcome Banner to use the DOD banner text below. 5. Check "Enable Banner". 6. Click "Save". Standard Mandatory DOD Notice and Consent Banner: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.
- RMF Control
- AU-10
- Severity
- M
- CCI
- CCI-000166
- Version
- NXAC-AS-000013
- Vuln IDs
-
- V-279423
- Rule IDs
-
- SV-279423r1191055_rule
Checks: C-83976r1191053_chk
Confirm the Nutanix VM application server Prism Element WebUI requires client authentication. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the "Authentication" section. 4. Click the "Client" tab. 5. Verify "Client Authentication" is enabled. If Client Authentication (CAC Auth) is not enabled, this is a finding.
Fix: F-83881r1191054_fix
Configure the Nutanix VM application server Prism Element WebUI to require client authentication. 1. Log in to Prism Element. 2. Click the gear in the upper-right corner and navigate to "Authentication". 3. Click the "Client" tab. 4. Select the "Configure Client Chain Certificate" check box. 5. Click the "Choose File" button, browse to and select a client chain certificate to upload, and then click the "Open" button to upload the certificate. 6. Click "Enable Client Authentication".
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- NXAC-AS-000014
- Vuln IDs
-
- V-279424
- Rule IDs
-
- SV-279424r1191058_rule
Checks: C-83977r1191056_chk
Confirm the Nutanix VM application server is configured to off-load log records onto a different system. $ ncli rsyslog-config ls-servers If no remote syslog servers are defined, this is a finding.
Fix: F-83882r1191057_fix
Configure the Nutanix VM application server to off-load log records onto a different system by running the following command: $ ncli rsyslog-config add-server name=<remote_server_name> relp-enabled=<true | false> ip-address=<remote_ip_address> port=<port_num> network-protocol=<tcp | udp>
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001855
- Version
- NXAC-AS-000016
- Vuln IDs
-
- V-279425
- Rule IDs
-
- SV-279425r1192580_rule
Checks: C-83978r1192579_chk
Confirm the NCC "CVM DISK | System Audit Volume Usage" is enabled and an alert is sent when the disk capacity reaches or exceeds 75 percent. 1. Log in to Prism Element. 2. Select "Health dashboard" from the navigation drop-down. 3. Select Actions >> Manage Checks. 4. Scroll to CVM | Disk section, and then select "System Audit Volume Usage". 5. Validate the Alert Policy settings for "Warning and Critical" are set to 75 percent. Confirm Nutanix AOS is set to send SMTP alerts to the email address(es) for the ISSO and SA, at a minimum. 1. Log in to Prism Element. 2. Select the "Health" dashboard. 3. On the "Actions" tab, review the setting for "Set NCC Frequency". If NCC alert settings are not configured as required, this is a finding.
Fix: F-83883r1192348_fix
Enable the NCC "CVM DISK | System Audit Volume Usage", set the threshold values, and verify an alert is sent when the disk capacity reaches or exceeds 75 percent. 1. Log in to Prism Element. 2. Select "Health" from the navigation drop-down. 3. Select Actions >> Manage Checks. 4. Scroll to :CVM | Disk" section, then select "System Audit Volume Usage". 5. If check is disabled, click to enable the check. 6. Select "Alert Policy", then set the values for "Warning" and "Critical" thresholds to 75 percent and click "Save". Configure NCC within Prism Element to send an alert and emails for ISSO and SA. 1. On the Actions tab, select "Set NCC Frequency". 2. Enter frequency timeframe. 3. Enter recipient email address(es).
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-000159
- Version
- NXAC-AS-000019
- Vuln IDs
-
- V-279426
- Rule IDs
-
- SV-279426r1191064_rule
Checks: C-83979r1191062_chk
Confirm Prism Element is set to use an authoritative time source to generate time stamps for log records. 1. Log in to Prism Element. 2. Select the gear icon in upper-right corner. 3. Select "NTP Servers" from the left navigation pane. If no authoritative time sources are listed, this is a finding.
Fix: F-83884r1191063_fix
Configure Prism Element to use organization-identified authoritative time sources. 1. Log in to Prism Element. 2. Select the gear icon in upper-right corner. 3. Select "NTP Servers" from the left navigation pane. 4. Enter authoritative time sources, then click "Add". Multiple time sources can be added.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- NXAC-AS-000020
- Vuln IDs
-
- V-279427
- Rule IDs
-
- SV-279427r1191067_rule
Checks: C-83980r1191065_chk
Confirm the Nutanix VM application server log files are protected from unauthorized read access. The Nutanix AOS log files are owned by the Nutanix user and have a file permission of "640". 1. Identify the actual file name by looking at alert_manager.INFO, which is a symlink for the actual rotating file name. $ sudo ls -al /home/nutanix/data/logs/alert_manager.INFO lrwxrwxrwx. 1 nutanix nutanix 75 Nov 1 17:50 /home/nutanix/data/logs/alert_manager.INFO -> alert_manager.ntnx-<CVM_NAME>.nutanix.log.INFO.<LOG_NUMBER> 2. Execute a stat command on the actual application server log file name. $ sudo stat -c "%a %n" /home/nutanix/data/logs/alert_manager.ntnx-<CVM_NAME>.nutanix.log.INFO.<LOG_NUMBER> 640 /home/nutanix/data/logs/alert_manager.ntnx<CVM_NAME>.nutanix.log.INFO.<LOG_NUMBER> If the output of the actual log file name is not 640, this is a finding.
Fix: F-83885r1191066_fix
Configure the Nutanix VM application server Prism Element log file permissions. 1. Run the following command: $ sudo salt-call state.sls security/CVM/interactivenutanixCVM 2. For Prism Central, run the following command: $ sudo salt-call state.sls security/PCVM/interactivenutanixPCVM 3. For Files, run the following command: $ sudo salt-call state.sls security/AFS/interactivenutanixAFS
- RMF Control
- Severity
- M
- CCI
- CCI-003831
- Version
- NXAC-AS-000023
- Vuln IDs
-
- V-279430
- Rule IDs
-
- SV-279430r1191372_rule
Checks: C-83983r1191074_chk
Verify the Nutanix NCC is set to send SMTP send alerts to the ISSO/ISSM (or designated personnel), at a minimum. The site can define a frequency that meets their needs. 1. Log in to Prism Element. 2. Select "Health dashboard". 3. In the "Actions" tab, select "Set NCC Frequency". If the organization-defined recipient(s) are not configured for the NCC, this is a finding.
Fix: F-83888r1191371_fix
Configure the NCC to alert the ISSO/ISSM or designated personnel, at a minimum. The site can define a frequency that meets their needs. 1. Log in to Prism Element. 2. Select "Health dashboard". 3. In the "Actions" tab, select "Set NCC Frequency". 4. Enter frequency timeframe. 5. Enter recipient email address(es).
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- NXAC-AS-000024
- Vuln IDs
-
- V-279431
- Rule IDs
-
- SV-279431r1191079_rule
Checks: C-83984r1191077_chk
Confirm Prism Element is set up with Role-Based Access Control (RBAC). 1. Log in to Prism Element. 2. Select the gear icon in the top-right corner. 3. Select "Authentication" from the left navigation pane. If no organization-approved directory (AD /LDAP) is listed, this is a finding. 4. Next, select "Role Mapping". If no role mappings are listed, this is a finding.
Fix: F-83889r1191078_fix
Configure the Nutanix VM application server Prism Element to use RBAC with an organization-approved directory (AD, LDAP). 1. Log in to Prism Element. 2. Select the gear icon in the top-right corner. 3. Select "Authentication" from the left navigation pane. 4. Add an authenticated organization-approved directory. 5. Set up role mappings for users and/or groups.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- NXAC-AS-000027
- Vuln IDs
-
- V-279433
- Rule IDs
-
- SV-279433r1191374_rule
Checks: C-83986r1191083_chk
Confirm the Nutanix VM application server is set to use enterprise user management systems. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the Authentication settings. If an Active Directory or OpenLDAP servers are not configured, this is a finding.
Fix: F-83891r1191373_fix
Configure the Nutanix VM application server to use an enterprise user management system to authenticate individual users. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the Authentication settings. 4. Add an Active Directory or OpenLDAP server to the directory list. Alternatively, create individual local users within Prism. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Local User Management". 4. Select "+ New Users".
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000765
- Version
- NXAC-AS-000028
- Vuln IDs
-
- V-279434
- Rule IDs
-
- SV-279434r1192622_rule
Checks: C-83987r1191086_chk
Verify the Nutanix AOS uses a centralized AAA server that uses DOD PKI to authenticate individual users. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the Authentication settings. If CAC authentication is not enabled, this is a finding.
Fix: F-83892r1191087_fix
Configure the Nutanix AOS to use a centralized AAA server that uses DOD PKI to authenticate individual users. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the Authentication settings. 4. Select the "Configure Service Account" check box and then complete the following in the indicated fields: a. Select the authentication directory that contains the CAC users to be authenticated. This list includes the directories configured on the Directory List tab. b. Service Username: Enter the username in the username@domain.com format the web console will use to log in to the Active Directory. c. Service Password: Enter the password for the service username. d. Click "Enable CAC".
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000765
- Version
- NXAC-AS-000029
- Vuln IDs
-
- V-279435
- Rule IDs
-
- SV-279435r1191091_rule
Checks: C-83988r1191089_chk
Confirm the Nutanix VM application server Envoy Reverse Proxy server only has one local account, and that it is the account of last resort. The Envoy Reverse Proxy server relies on AD for user management. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. If an Active Directory or OpenLDAP servers are not configured, this is a finding.
Fix: F-83893r1191090_fix
Configure the Nutanix VM application server to use an enterprise user management system to authenticate individual users. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Add an Active Directory or OpenLDAP server to the directory list. Alternatively, individual local users can be created within Prism. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Local User Management. 4. Select "+ New Users".
- RMF Control
- Severity
- M
- CCI
- CCI-004045
- Version
- NXAC-AS-000032
- Vuln IDs
-
- V-279438
- Rule IDs
-
- SV-279438r1191100_rule
Checks: C-83991r1191098_chk
Confirm the Nutanix VM application server is set to use enterprise user management systems. Envoy Reverse Proxy does not support group authenticators. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. If an Active Directory or OpenLDAP servers are not configured, this is a finding.
Fix: F-83896r1191099_fix
Configure the Nutanix VM application server to use an enterprise user management system to authenticate individual users. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Add an Active Directory or OpenLDAP server to the directory list. Alternatively, individual local users can be created within Prism. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Local User Management. 4. Select "+ New Users".
- RMF Control
- Severity
- M
- CCI
- CCI-004047
- Version
- NXAC-AS-000034
- Vuln IDs
-
- V-279439
- Rule IDs
-
- SV-279439r1191103_rule
Checks: C-83992r1191101_chk
Confirm the Prism Element WebUI requires client authentication. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication. 4. Click the "Client" tab. 5. Verify client authentication is enabled. If client authentication is not enabled, this is a finding.
Fix: F-83897r1191102_fix
Configure the Prism Element WebUI to require client authentication. 1. Log in to Prism Element. 2. Click the gear in the upper-right corner and navigate to Authentication. 3. Click the "Client" tab. 4. Select the "Configure Client Chain Certificate" check box. 5. Click "Choose File", browse to and select a client chain certificate to upload, and then click "Open" to upload the certificate. 6. Click "Enable Client Authentication".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- NXAC-AS-000035
- Vuln IDs
-
- V-279440
- Rule IDs
-
- SV-279440r1191106_rule
Checks: C-83993r1191104_chk
Confirm the Nutanix Envoy Reverse Proxy is set to use encryption when using LDAP. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Verify an Active Directory or OpenLDAP server is on the directory list. If an Active Directory or OpenLDAP servers are not using ports 636 or 3269, which are SSL encrypted, this is a finding.
Fix: F-83898r1191105_fix
Configure the Nutanix VM application server to use an Active Directory server to authenticate individual users. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Add an Active Directory or OpenLDAP server to the directory list using SSL encrypted ports 636 or 3269.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-002007
- Version
- NXAC-AS-000036
- Vuln IDs
-
- V-279441
- Rule IDs
-
- SV-279441r1191109_rule
Checks: C-83994r1191107_chk
Confirm the Nutanix AOS session timeout settings are set to 10 minutes. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "UI Settings" in the left navigation pane. For each user type, verify the session timeout is set correctly. If not, this is a finding.
Fix: F-83899r1191108_fix
Configure the Nutanix AOS session timeout settings to 10 minutes. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "UI Settings" in the left navigation pane. 4. Set the session timeout settings to 10 minutes per user type.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- NXAC-AS-000038
- Vuln IDs
-
- V-279442
- Rule IDs
-
- SV-279442r1192581_rule
Checks: C-83995r1192350_chk
Confirm the Nutanix VM application server has OCSP checking enabled. Run the following command: $ ncli authconfig get-client-authentication-config 'Auth Config Status : true' If "Auth config status" is not set to "true", this is a finding.
Fix: F-83900r1192351_fix
Configure the Nutanix VM application server to use OSCP for certificate revocation. Set the OCSP responder URL: $ ncli authconfig set-certificate-revocation set-ocsp-responder=<ocsp url><ocsp url>
- RMF Control
- Severity
- M
- CCI
- CCI-004083
- Version
- NXAC-AS-000042
- Vuln IDs
-
- V-279443
- Rule IDs
-
- SV-279443r1192354_rule
Checks: C-83996r1192353_chk
If configured, Confirm the Nutanix VM application server Prism Element is configured to accept FICAM-approved third party credentials. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Verify a SAML-based identity provider is configured. If a SAML-based identity provider is not configured, this is a finding.
Fix: F-83901r1191114_fix
Configure the Nutanix VM application server Prism Element to use FICAM authentication. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Select "Configure SAML Authentication Account" check box, and then do the following in the indicated fields: a. Select the authentication directory that contains the CAC users to authenticate. This list includes the directories that are configured on the directory list tab. b. Service Username: Enter the username in the username@domain.com for the web console to use to log in to the Active Directory. c. Service Password: Enter the password for the service username. d. Click "Enable CAC".
- RMF Control
- Severity
- M
- CCI
- CCI-004085
- Version
- NXAC-AS-000043
- Vuln IDs
-
- V-279444
- Rule IDs
-
- SV-279444r1192356_rule
Checks: C-83997r1192355_chk
Confirm the Nutanix VM application server Prism Element is configured to accept FICAM-approved third party credentials. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Verify a SAML-based identity provider is configured. If a SAML-based identity provider is not configured this is a finding.
Fix: F-83902r1191117_fix
Configure the Nutanix VM application server Prism Element to use FICAM authentication. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Select the "Configure SAML Authentication Account" check box, and then do the following in the indicated fields: a. Select the authentication directory that contains the CAC users to authenticate. This list includes the directories that are configured on the Directory List tab. b. Service Username: Enter the username in the username@domain.com format that you want the web console to use to log in to the Active Directory. c. Service Password: Enter the password for the service username. d. Click "Enable CAC".
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- NXAC-AS-000045
- Vuln IDs
-
- V-279445
- Rule IDs
-
- SV-279445r1192540_rule
Checks: C-83998r1192538_chk
Confirm the Nutanix VM application server is configured with a trusted DOD root CA-signed certificate. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the SSL Certificate section. 4. Ensure the approved CA signed certificate is installed. If the certificate used is not from an approved DOD-approved CA, this is a finding.
Fix: F-83903r1192539_fix
Configure the Nutanix VM application server to use a trusted DOD root CA-signed certificate. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to the SSL Certificate section. 4. Click "Relace Certificate". 5. Select "Import Key and Certificate". 6. Select the Private Key Type and upload the private key, public certificate, and the CA certificate or chain. 7. Select "Import Files".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- NXAC-AS-000046
- Vuln IDs
-
- V-279446
- Rule IDs
-
- SV-279446r1192360_rule
Checks: C-83999r1192359_chk
Confirm the Nutanix VM application server is set to use data-at-rest encryption. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Data-at-Rest Encryption". 4. Verify software encryption is enabled. If software encryption is not enabled, this is a finding.
Fix: F-83904r1191123_fix
Configure the Nutanix VM application server to use data-at-rest encryption. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Data-at-Rest Encryption". 4. Select "Edit configuration". 5. Select either the cluster local KMS or an external KMS. 6. Click "Protect" and confirm by typing "ENCRYPT".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- NXAC-AS-000047
- Vuln IDs
-
- V-279447
- Rule IDs
-
- SV-279447r1192582_rule
Checks: C-84000r1192361_chk
Confirm the Nutanix VM application server is set to use data-at-rest encryption when stored offline. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Data-at-Rest Encryption". 4. Verify software encryption is enabled. If software encryption is not enabled, this is a finding.
Fix: F-83905r1191126_fix
Configure the Nutanix VM application server to use data-at-rest encryption when stored offline. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Data-at-Rest Encryption". 4. Select "Edit configuration". 5. Select either the cluster local KMS or an external KMS. 6. Click "Protect" and confirm by typing "ENCRYPT".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-002475
- Version
- NXAC-AS-000048
- Vuln IDs
-
- V-279448
- Rule IDs
-
- SV-279448r1192364_rule
Checks: C-84001r1192363_chk
Confirm the Nutanix VM application server is configured to enable data-at-rest encryption. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Data-at-Rest Encryption". 4. Verify software encryption is enabled. If encryption is not enabled, this is a finding.
Fix: F-83906r1191375_fix
Configure the Nutanix VM application server to enable data-at-rest encryption. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Data-at-Rest Encryption". 4. Select "Edit configuration". 5. Select either the cluster local KMS or an external KMS. 6. Click "Protect" and confirm by typing "ENCRYPT".
- RMF Control
- Severity
- M
- CCI
- CCI-004922
- Version
- NXAC-AS-000051
- Vuln IDs
-
- V-279450
- Rule IDs
-
- SV-279450r1192366_rule
Checks: C-84003r1192365_chk
Confirm the Prism Element is configured to use an authoritative NTP source. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "NTP Servers". 4. Verify external NTP servers have been configured. If external NTP sources are not configured, this is a finding.
Fix: F-83908r1191135_fix
Configure the Prism Element to use an authoritative NTP time source. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "NTP Servers". 4. Configure an authoritative NTP server.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001314
- Version
- NXAC-AS-000054
- Vuln IDs
-
- V-279451
- Rule IDs
-
- SV-279451r1192368_rule
Checks: C-84004r1192367_chk
Nutanix VM application server supports user and group role mapping. Verify that all users or groups match that of the documented mapping policies defined by the information system security officer (ISSO). 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Role mapping". For each user or group listed, verify the role granted is in accordance with access control policies. If not, this is a finding.
Fix: F-83909r1191379_fix
Configure the user and group mappings to be compliant with the documented mapping policies defined by the ISSO. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Role mapping". 4. Add users and groups to role mappings per policy.
- RMF Control
- AU-14
- Severity
- M
- CCI
- CCI-001464
- Version
- NXAC-AS-000067
- Vuln IDs
-
- V-279464
- Rule IDs
-
- SV-279464r1192371_rule
Checks: C-84017r1192369_chk
Verify Prism Element enables logging upon startup of Envoy proxy services by running the following command: $ ps -ef | grep ikat_proxy.out nutanix 68158 1 0 Oct10 ? 00:00:00 /bin/bash -lc /home/nutanix/bin/service_monitor --run_as_user=apache /home/nutanix/data/logs/ikat_proxy.FATAL -- /usr/local/nutanix/ikat_proxy/bin/envoy -c /home/nutanix/config/ikat_proxy/envoy.yaml --disable-hot-restart --concurrency 4 |& /home/nutanix/bin/logpipe -o /home/nutanix/data/logs/ikat_proxy.out nutanix 68376 68158 0 Oct10 ? 00:00:01 /home/nutanix/bin/logpipe -o /home/nutanix/data/logs/ikat_proxy.out If the output of "ikat_proxy.out" does not list the path as "/home/nutanix/data/logs/ikat_proxy.out", or if there is no output, this is a finding.
Fix: F-83922r1192370_fix
Prism Element is configured by default for the Envoy proxy services with logging level of "info". If this control is a finding, then some corruption has occurred and the VM must be rebuilt.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- NXAC-AS-000089
- Vuln IDs
-
- V-279486
- Rule IDs
-
- SV-279486r1192542_rule
Checks: C-84039r1191242_chk
Management information flow can be isolated to a separate VLAN from the guest VMs. Verify a management LAN is configured. 1. Log in to Prism Element. 2. Click the gear icon in the upper right-corner. 3. Under the "Settings" menu, click "Network Configuration", then select the "Internal Interfaces" tab. 4. Click "Management LAN". If "VLAN ID" is "0" or blank, this is a finding.
Fix: F-83944r1192541_fix
Configure management information flow to isolate to a separate VLAN from the guest VMs. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Under the "Settings" menu, click "Network Configuration", then select the "Internal Interfaces" tab. 4. Click "Management LAN". 5. Set the VLAN to the VLAN used for management functions. a. SSH into each CVM host as user "Nutanix" and issue the following command: change_cvm_vlan vlan_id. b. SSH into each AHV host as root and issue the following command: ovs-vsctl set port br0 tag=vlan_id Note: All network switches connected to Nutanix nodes must be appropriately configured with the same VLAN ID.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- NXAC-AS-00067
- Vuln IDs
-
- V-279526
- Rule IDs
-
- SV-279526r1191364_rule
Checks: C-84079r1191362_chk
Validate Nutanix CVM VM networking has been implemented and all of the virtual networks are defined and documented by the information system security officer (ISSO). 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Network Configuration". Validate that all of the organizational-defined guest VM networks are defined. If not, this is a finding.
Fix: F-83984r1191363_fix
Add the guest VM networks. All interactions between guest VMs and external systems via other interface devices are mediated by the VMM or its service VMs. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to "Network Configuration". 4. Add the guest VM networks as defined by the organization.