SRG-APP-000429-WSR-000113
search cancel

SRG-APP-000429-WSR-000113

book

Article ID: 205007

calendar_today

Updated On:

Products

CA Infrastructure Management CA Performance Management - Usage and Administration DX NetOps

Issue/Introduction

STIG ID: SRG-APP-000429-WSR-000113
Rule Title: The web server must encrypt user identifiers and passwords.

Discussion: When data is written to digital media, such as hard drives, mobile computers, external/removable hard drives, personal digital assistants, flash/thumb drives, etc., there is risk of data loss and data compromise. User identities and passwords stored on the hard drive of the hosting hardware must be encrypted to protect the data from easily being discovered and used by an unauthorized user to access the hosted applications. The cryptographic libraries and functionality used to store and retrieve the user identifiers and passwords must be part of the web server.

Environment

DX NetOps Performance Management 3.7

Cause

https://www.stigviewer.com/stig/web_server_security_requirements_guide/2015-08-28/finding/V-56031

Resolution

Database passwords are encrypted in the database as well as dbconnection.cfg.  Usernames are not encrypted