OSX00121 - Disable clear text passwords for all LDAPv3 directories

Information

Disable the use of clear text passwords when accessing LDAPv3 directories.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Finder
Click Applications
Double Click Utility
Double Click Directory Utility
Click the Show Advanced Options button
Click Services tab
Click the Lock and enter the password to unlock the options(if needed)
Click the LDAPv3 service
Click the Pencil icon
Highlight the Server Name/Configuration Name
Click Edit
Click the Security tab and select 'Disable clear text passwords'

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

References: CAT|I, Rule-ID|SV-31775r1_rule, STIG-ID|OSX00121, Vuln-ID|V-25557

Plugin: Unix

Control ID: 69c36920162318f6310613c189ecf75f9969f4a6b468baa7a0dbc608ce6bd6da