1.2.8 Ensure passwordFormat Credentials Element Not Set To Clear

Information

Authentication credentials should always be protected to reduce the risk of stolen authentication credentials.

Solution

Authentication mode is configurable at the machine.config, root-level web.config, or application-level web.config: Locate and open the configuration file where the credentials are stored Find the <credentials> element If present, ensure passwordFormat is not set to Clear Change passwordFormat to SHA1 or MD5 The clear text passwords will need to be replaced with the appropriate hashed version.

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv6|16.13, CSCv6|16.14

Plugin: Windows

Control ID: b7cd03d1dd092a4eb874aac2ebbcd4050f271e6d264a7f938b3e6e2654df8703