SV-100953r1_rule
V-90303
SRG-APP-000015-WSR-000014
VRAU-HA-000020
CAT II
10
Navigate to and open the following files:
/etc/haproxy/conf.d/20-vcac.cfg
/etc/haproxy/conf.d/30-vro-config.cfg
Configure the bind option for each frontend with the "ssl" parameter.
Navigate to and open the following files:
/etc/haproxy/conf.d/20-vcac.cfg
/etc/haproxy/conf.d/30-vro-config.cfg
Verify that each frontend is configured with the following:
bind :<port> ssl crt <pemfile> ciphers FIPS:+3DES:!aNULL no-sslv3
Note: <port> and <pemfile> will be different for each frontend.
If "ssl" is not set for the bind option for each frontend, this is a finding.
V-90303
False
VRAU-HA-000020
Navigate to and open the following files:
/etc/haproxy/conf.d/20-vcac.cfg
/etc/haproxy/conf.d/30-vro-config.cfg
Verify that each frontend is configured with the following:
bind :<port> ssl crt <pemfile> ciphers FIPS:+3DES:!aNULL no-sslv3
Note: <port> and <pemfile> will be different for each frontend.
If "ssl" is not set for the bind option for each frontend, this is a finding.
M
3455