Management Access Policy - HTTPS - Allow Credentials

Information

Set the Access-Control-Allow-Credentials header in the web server responses. Required in Cross-Origin Resource Sharing (CORS) scenario.
- Disabled
- Enabled

The default is Disabled.

Solution

Log into the Cisco APIC Web Console:
Navigate to 'Fabric' -> 'Fabric Policies'.

Click 'Fabric Security'.

Expand 'Policies'

Expand 'Pod'

Expand 'Management Access'

For each 'Management Access' policy, in the 'HTTPS' section, ensure 'Allow Credentials' is set to 'Disabled'.

Item Details

Audit Name: Tenable Cisco ACI

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Cisco_ACI

Control ID: 94602c866dd02ebb450a51183fef893b948718e2f87fe706e18419e7a4cbfe67