SYMP-AG-000410 - Symantec ProxySG, when configured for reverse proxy/WAF services and providing PKI-based user authentication intermediary services, must map the client certificate to the authentication server store.

Information

Authorization for access to any network element requires an approved and assigned individual account identifier. To ensure only the assigned individual is using the account, the account must be bound to a user certificate when PKI-based authentication is implemented.

This requirement applies to ALGs that provide user authentication intermediary services (e.g., authentication gateway or TLS gateway). It does not apply to authentication for the purpose of configuring the device itself (device management).

Solution

Configure the ProxySG to map PKI user credentials to user identities in a reverse proxy configuration.

1. Log on to the Web Management Console.
2. Browse to Configuration >> Services >> Proxy Services.
3. Click each HTTPS Reverse Proxy service and click 'Edit Service'.
4. Check the 'Verify Client' option and click 'Apply'.
5. Configure all remaining options in accordance with the site's SSP.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SYM_ProxySG_Y20M04_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(c), CAT|II, CCI|CCI-000187, Rule-ID|SV-104249r1_rule, STIG-ID|SYMP-AG-000410, Vuln-ID|V-94295

Plugin: BlueCoat

Control ID: 86c51a7a71d08f075dc7318ed472a2411863e54d9afe4413b7fbd4c9f2c63210