The ALG providing PKI-based user authentication intermediary services must map authenticated identities to the user account.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-204951
SRG-NET-000166-ALG-000101
SV-204951r395988_rule
Medium
Description
Authorization for access to any network element requires an approved and assigned individual account identifier. To ensure only the assigned individual is using the account, the account must be bound to a user certificate when PKI-based authentication is implemented.
This requirement applies to ALGs that provide user authentication intermediary services (e.g., authentication gateway or TLS gateway). This does not apply to authentication for the purpose of configuring the device itself (device management).