Automation Controller must utilize encryption when using LDAP for authentication.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256907APAS-AT-000055SV-256907r961029_ruleCCI-000197medium
Description
To avoid access with malicious intent, passwords will need to be protected at all times. This includes transmission where passwords must be encrypted for security.
STIGDate
Red Hat Ansible Automation Controller Application Server Security Technical Implementation Guide2025-05-23

Details

Check Text (C-256907r961029_chk)

Log in to Automation Controller as an administrator and navigate to Settings >> Authentication >> LDAP settings. If an LDAP server is configured but the "LDAP SERVER URI" field does not start with "ldaps://", this is a finding.

Fix Text (F-60524r903514_fix)

Log in to Automation Controller as an administrator and navigate to Settings >> Authentication >> LDAP settings. Click "Edit". Modify the "LDAP SERVER URI" field so that it begins with "ldaps://". Click "Save".