Check: 5.124
Windows Vista STIG:
5.124
(in versions v6 r42 through v6 r41)
Title
Client computers required to authenticate for RPC communication. (Cat II impact)
Discussion
This check verifies that the system is configured to force client computers to provide authentication before an RPC communication is established.
Check Content
If the following registry value doesn’t exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows NT\Rpc\ Value Name: EnableAuthEpResolution Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Remote Procedure Call “RPC Endpoint Mapper Client Authentication” to “Enabled.
Additional Identifiers
Rule ID: SV-29410r1_rule
Vulnerability ID: V-14254
Group Title: RPC - Endpoint Mapper Authentication
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001967 |
The information system authenticates organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based. |
Controls
Number | Title |
---|---|
IA-3 (1) |
Cryptographic Bidirectional Authentication |