3.2.1.20 Ensure 'Allow pairing with non-Configurator hosts' is set to 'Disabled'

Information

This recommendation pertains to allowing data communication with a host computer.

Rationale:

Host pairing is a process by which an iOS or iPadOS device creates a cryptographically verified connection with a trusted host computer. By disabling the addition of new host pairings, a variety of hardware-based attacks on the device are blocked.

Impact:

An end user will not be able to sync media to and from the device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the Restrictions tab.

In the right window pane, under the tab Functionality, uncheck the checkbox for Allow pairing with non-Configurator hosts.

Deploy the Configuration Profile.

Additional Information:

There are two important pieces of data on the Apple Configurator host. The login keychain will include the host's identity certificate and may be exported. The escrow keybags related to each device will be found in /var/db/lockdown. It is important that both these be backed up for continuity of device management. They may also be duplicated to other Macs to allow management of the configured devices.

See Also

https://workbench.cisecurity.org/benchmarks/6168