Check: BEMS-03-015100
BlackBerry Enterprise Mobility Server 3.x STIG:
BEMS-03-015100
(in versions v1 r2 through v1 r1)
Title
If the BlackBerry Docs service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable the proxy server authentication type (if a proxy is used). (Cat II impact)
Discussion
The web proxy provides a secure gateway for the BlackBerry Docs service so that BEMS can securely connect to enterprise servers.
Check Content
This requirement is not applicable if the Docs service for BEMS is not enabled. Verify that the authentication type is set to NTLM if a web proxy is used. 1. Under the "BlackBerry Services Configuration", select "Docs". 2. Under the "Proxy Server Authentication Type", ensure "NTLM" is Selected. If "NTLM" is not selected, this is a finding.
Fix Text
Configure the Docs Web Proxy Authentication type within BEMS. 1. Under the "BlackBerry Services Configuration", select "Docs". 2. Select "Web Proxy Configuration". 3. Under "Proxy Server Authentication Type" Select "NTLM".
Additional Identifiers
Rule ID: SV-254732r879887_rule
Vulnerability ID: V-254732
Group Title: SRG-APP-000516-AS-000237
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |