Rule ID
SV-279438r1191100_rule
Version
V1R1
CCIs
To ensure individual accountability and prevent unauthorized access, application server users (and any processes acting on behalf of application server users) must be individually identified and authenticated. A group authenticator is a generic account used by multiple individuals. Use of a group authenticator alone does not uniquely identify individual users. Application servers must ensure individual users are authenticated prior to authenticating via role or group authentication. This is to ensure there is nonrepudiation for actions taken.
Confirm the Nutanix VM application server is set to use enterprise user management systems. Envoy Reverse Proxy does not support group authenticators. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. If an Active Directory or OpenLDAP servers are not configured, this is a finding.
Configure the Nutanix VM application server to use an enterprise user management system to authenticate individual users. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Authentication settings. 4. Add an Active Directory or OpenLDAP server to the directory list. Alternatively, individual local users can be created within Prism. 1. Log in to Prism Element. 2. Click the gear icon in the upper-right corner. 3. Navigate to Local User Management. 4. Select "+ New Users".