Rule ID
SV-285296r1258939_rule
Version
V1R1
CCIs
The purpose of requiring a device that is separate from the system to which the user is attempting to gain access for one of the factors during multifactor authentication is to reduce the likelihood of compromising authenticators or credentials stored on the system. Adversaries may be able to compromise such authenticators or credentials and subsequently impersonate authorized users. Implementing one of the factors on a separate device (e.g., a hardware token), provides a greater strength of mechanism and an increased level of assurance in the authentication process.
Verify Infoblox is configured to use multifactor authentication. Review the configuration of external authentication methods to verify multifactor authentication is enabled. 1. Navigate to Administration >> Administrators >> Authentication Policy tab. 2. Ensure multifactor authentication is configured by validating that the multiple authentication methods are enabled to include at least one remote authentication service. Note: When an administrator logs in with a user name and password, Infoblox uses the first service listed in the authentication policy to perform the authentication. If authentication fails, it tries the next service listed, and so on, until it is successful or all services fail. If all services fail, then the appliance denies access and generates an error message in the syslog. Note: Grid Manager must display the "Two-Factor Authentication Enabled" banner in this tab. If the aggregate authentication policy does not provide two or more factors, this is a finding.
Configure at least one remote authentication group (OCSP, TACACS+, RADIUS, LDAP, or Active Directory). Note: Refer to the Infoblox Administrator Guide for details on each type of authentication server. 1. Navigate to Administration >> Administrators >> Authentication Policy tab. 2. From the "Authenticate users against these services in this order" section, click the "Add" icon to add an authentication server group (Active Directory, LDAP, RADIUS, SAML, TACACS+, or Certificate Authentication Service). 3. Click "Add". Note: Reorder the list by selecting an authentication server group and moving it up or down the list using the arrow keys. 4. Perform a service restart if necessary.