Skip to content

The Sentry that provides intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52.

An XCCDF Rule

Description

SP 800-52 provides guidance on using the most secure version and configuration of the TLS/SSL protocol. Using older unauthorized versions or incorrectly configuring protocol negotiation makes the gateway vulnerable to known and unknown attacks which exploit vulnerabilities in this protocol.

ID
SV-251013r802261_rule
Version
MOIS-AL-000180
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the Sentry to comply with applicable required TLS settings in NIST PUB SP 800-52.

1. Log in to MobileIron Sentry.
2. Go to Settings >> Services >> Sentry.
3. For each of the following configurations, follow the step 4 procedure: 
     a. Incoming SSL configuration