Skip to main content

January 9, 2025

DISA STIG OS Compliance Guidelines for Omnissa Unified Access Gateway

Unified Access Gateway supports configuration settings to allow Unified Access Gateway to comply with the Photon 4.0 OS Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG).

This OS compliance requires specific configuration in the Unified Access Gateway appliance.

The configuration changes are listed as follows:

  1. Deploy the FIPS version of Unified Access Gateway.
  2. Configure the following parameters during deployment.

Note: You can configure these parameters only at the time of deployment. If you do not configure during deployment, Unified Access Gateway includes the default values.

ParameterDescription
dsComplianceOSSet to true to enable DISA STIG OS compliance settings.
rootPasswordExpirationDaysNumber of days after which the root password must be mandatorily reset. Set the value to 90.
passwordPolicyMinLenMinimum length of the root password. Set the value to 8.
passwordPolicyMinClassMinimum complexity of the root password. Set the value to 4.
sshEnabledSet to true to automatically enable SSH access on the deployed appliance.
sshLoginBannerTextSet to an appropriate login banner that includes the text You are accessing a U.S. Government System.
rootSessionIdleTimeoutSecondsDuration in seconds after which an idle session of the root user will expire. Set the value to 900.
passwordPolicyFailedLockoutNumber of failed login attempts after which admin user access is locked out temporarily. Set the value to 3.
sshInterfaceSet to eth0, eth1 or eth2 according to which Unified Access Gateway NIC SSH is accessed. For example, sshInterface=eth0.
sshPortSet to an unused port value other than port 22. For example, sshPort=30.
syslogUrlSet the syslog URL. For example, syslog://mysyslog.example.int:514.
ntpServers Set the hostname(s) for NTP servers. For example, mytimesvr1.example.int, mytimesvr1.example.int.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…