3.2.1.18 Ensure 'Allow pairing with non-Configurator hosts' is set to 'Disabled'

Information

This recommendation pertains to allowing data communication with a host computer.

Rationale:

Host pairing is a process by which an iOS or iPadOS device creates a cryptographically verified connection with a trusted host computer. By disabling the addition of new host pairings, a variety of hardware based attacks on the device are blocked.

Impact:

An end-user will not be able to sync media to and from the device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left windowpane, click on the Restrictions tab.

In the right windowpane, under the tab Functionality, uncheck the checkbox for Allow pairing with non-Configurator hosts.

Deploy the Configuration Profile.

Additional Information:

On the Apple Configurator host, there are two important data. The login keychain will include the host's identity certificate. It may be exported. The escrow keybags related to each device will be found in /var/db/lockdown. It is important that both these be backed up for continuity of device management. They may also be duplicated to other Macs to allow management of the configured devices.

See Also

https://workbench.cisecurity.org/files/3064