PGS9-00-011800 - PostgreSQL must map the PKI-authenticated identity to an associated user account.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The DoD standard for authentication is DoD-approved PKI certificates. Once a PKI certificate has been validated, it must be mapped to PostgreSQL user account for the authenticated identity to be meaningful to PostgreSQL and useful for authorization decisions.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure PostgreSQL to map authenticated identities directly to PostgreSQL user accounts.

For information on configuring PostgreSQL to use SSL, see supplementary content APPENDIX-G.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_PGS_SQL_9-x_V2R4_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000187, Rule-ID|SV-214149r879614_rule, STIG-ID|PGS9-00-011800, STIG-Legacy|SV-87707, STIG-Legacy|V-73055, Vuln-ID|V-214149

Plugin: Unix

Control ID: cb0d416358b0d9f5e57cfcadbefdc3ccc1174906ad0d625406836287235d5cff