SV-100951r1_rule
V-90301
SRG-APP-000014-WSR-000006
VRAU-HA-000015
CAT II
10
Navigate to and open the following files:
/etc/haproxy/conf.d/20-vcac.cfg
/etc/haproxy/conf.d/30-vro-config.cfg
Configure the bind option for each frontend with the following ciphers parameter:
'ciphers FIPS:+3DES:!aNULL'.
Navigate to and open the following files:
/etc/haproxy/conf.d/20-vcac.cfg
/etc/haproxy/conf.d/30-vro-config.cfg
Verify that each frontend is configured with the following:
bind :<port> ssl crt <pemfile> ciphers FIPS:+3DES:!aNULL no-sslv3
Note: <port> and <pemfile> will be different for each frontend.
If the ciphers listed are not as shown above, this is a finding.
V-90301
False
VRAU-HA-000015
Navigate to and open the following files:
/etc/haproxy/conf.d/20-vcac.cfg
/etc/haproxy/conf.d/30-vro-config.cfg
Verify that each frontend is configured with the following:
bind :<port> ssl crt <pemfile> ciphers FIPS:+3DES:!aNULL no-sslv3
Note: <port> and <pemfile> will be different for each frontend.
If the ciphers listed are not as shown above, this is a finding.
M
3455