Unified Access Gateway supports configuration settings to allow to comply with Security Technical Implementation Guide (STIG) based on the CloudLinux AlmaLinux OS 9 STIG - Ver 1, Rel 1 guidelines. See National Checklist Program's checklist for Alma Linux 9 security configuration guidelines.
To achieve compliance, deploy the FIPS-compliant version of Unified Access Gateway appliance by configuring the following parameters during the deployment process.
| Parameter | Description |
|---|---|
| dsComplianceOS | Set to true to enable DISA STIG OS compliance settings. |
| rootPasswordExpirationDays | Number of days after which the root password must be mandatorily reset.
Set the value to 60. |
| passwordPolicyMinLen | Minimum length of the root password.
Set the value to 15. |
| passwordPolicyMinClass | Minimum complexity of the root password.
Set the value to 4. |
| sshEnabled | Set to true to automatically enable SSH access on the deployed appliance. |
| DNS | Ensure the configuration includes at least two DNS servers, one as the primary (active) and the other as the secondary (backup). |
Post deployment, configure the following parameter using the Admin UI.
| Parameter | Description |
|---|---|
| syslogUrl | Set the syslog server URL to use TLS as the communication protocol. |
Was this page helpful?