O112-C2-015501 - Processes (services, applications, etc.) that connect to the DBMS independently of individual users, must use valid, current DoD-issued PKI certificates for authentication to the DBMS.

Information

Just as individual users must be authenticated, and just as they must use PKI-based authentication, so must any processes that connect to the DBMS.

The DoD standard for authentication of a process or device communicating with another process or device is the presentation of a valid, current, DoD-issued Public Key Infrastructure (PKI) certificate that has previously been verified as Trusted by an administrator of the other process or device.

This applies both to processes that run on the same server as the DBMS and to processes running on other computers.

The Oracle-supplied super-user account, SYS, is an exception. It cannot currently use certificate-based authentication. For this reason among others, use of SYS should be restricted to where it is truly needed.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

For each such account, use DoD certificate-based authentication.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11-2g_V2R3_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(c), CAT|II, CCI|CCI-000187, Rule-ID|SV-219777r397600_rule, STIG-ID|O112-C2-015501, STIG-Legacy|SV-67497, STIG-Legacy|V-53281, Vuln-ID|V-219777

Plugin: OracleDB

Control ID: ae0edc13bcdbbc8e6a3ddc6425bd2f7612c7136a8eed4f0ddd0a12eef2023d88