Check: BEMS-03-014900
BlackBerry Enterprise Mobility Server 3.x STIG:
BEMS-03-014900
(in versions v1 r2 through v1 r1)
Title
If the BlackBerry Connect service is installed on the BlackBerry Enterprise Mobility Server (BEMS), it must be configured to enable the Web Proxy. (Cat II impact)
Discussion
The web proxy provides a secure gateway for the BlackBerry Connect service so that BEMS can securely connect to the internet.
Check Content
This requirement is not applicable if the Connect service is not enabled on BEMS. Verify that Web Proxy Configuration has been configured. 1. Under "BlackBerry Services Configuration" select "Connect". 2. Select "Web Proxy". 3. Confirm "Use Web Proxy" has been checked. If "Use Web Proxy" has not been selected, this is a finding.
Fix Text
Configure Web Proxy Configuration for the Connect service. 1. In the BEMS dashboard under "BlackBerry Services Configuration" click "Connect". 2. Click "Web Proxy". 3. Check the box for "Use Web Proxy". 4. Add "Proxy Address". 5. Add "Proxy Port". 6. Set "Proxy Server Authentication Type" to "Digest".
Additional Identifiers
Rule ID: SV-254730r879887_rule
Vulnerability ID: V-254730
Group Title: SRG-APP-000516-AS-000237
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |