OSX00120 - LDAP Authentication, Use authentication when connecting to LDAPv3.

Information

When configuring LDAPv3 for LDAP authentication, do not add DHCP-supplied LDAP servers to automatic search policies if you cannot secure the network the computer is running on. If you do, someone can create a rogue DHCP. Use authentication when connecting to LDAPv3 directories and disable clear text passwords for all LDAPv3 directories. Digitally sign all LDAPv3 packets (requires Kerberos). Encrypt all LDAPv3 packets (requires SSL or Kerberos). Block man-in-the-middle attacks (requires Kerberos).

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Finder
Click Applications
Double Click Utility
Double Click Directory Utility
Click the Show Advanced Options button
Click Services tab
Click the Lock and enter the password to unlock the options(if needed)
Click the LDAPv3 service
Click the Pencil icon
Highlight the Server Name/Configuration Name
Click Edit
Click on Security tab and select 'Use authentication when connecting'

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

References: CAT|II, Rule-ID|SV-31325r1_rule, STIG-ID|OSX00120, Vuln-ID|V-25264

Plugin: Unix

Control ID: ad157c11db0b7fd441016d86c3221d0cf8a75a0c07c5cecb6044ec92d69b720b