Check: EPAS-00-011900
EnterpriseDB Postgres Advanced Server (EPAS) STIG:
EPAS-00-011900
(in version v1 r1)
Title
The EDB Postgres Advanced Server must generate audit records when unsuccessful logons or connection attempts occur. (Cat II impact)
Discussion
For completeness of forensic analysis, it is necessary to track failed attempts to log on to the DBMS. While positive identification may not be possible in a case of failed authentication, as much information as possible about the incident must be captured.
Check Content
Execute the following SQL as the "enterprisedb" operating system user: > psql edb -c "SHOW edb_audit_connect" If the result is not "all" or if the current setting for this requirement has not been noted and approved by the organization in the system documentation, this is a finding.
Fix Text
Execute the following SQL as the "enterprisedb" operating system user: > psql edb -c "ALTER SYSTEM SET edb_audit_connect = 'all'" > psql edb -c "ALTER SYSTEM SET edb_audit_disconnect = 'all'" > psql edb -c "SELECT pg_reload_conf()" or Update the system documentation to note the organizationally approved setting and corresponding justification of the setting for this requirement.
Additional Identifiers
Rule ID: SV-259317r939004_rule
Vulnerability ID: V-259317
Group Title: SRG-APP-000503-DB-000351
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000172 |
The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |