OSX00122 - Digitally sign all LDAPv3 packets

Information

To protect the data between the client and LDAPv3 directory the traffic should be digitally signed.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Finder
Click Applications
Double Click Utility
Double Click Directory Utility
Click the Show Advanced Options button
Click Services tab
Click the Lock and enter the password to unlock the options(if needed)
Click the LDAPv3 service
Click the Pencil icon
Highlight the Server Name/Configuration Name
Click Edit
Click on Security tab and select 'Digitally sign all packets (requires Kerberos)'

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

References: CAT|II, Rule-ID|SV-31778r1_rule, STIG-ID|OSX00122, Vuln-ID|V-25559

Plugin: Unix

Control ID: 3f7b03dea4764dcefd30353784e5907f96ae18cbecb5fdc0d1858c2d2ea7e46a