SV-104541r1_rule
V-94711
SRG-APP-000411-NDM-000330
SYMP-NM-000300
CAT I
10
Configure the ProxySG to use only FIPS compliant HMAC algorithms.
1. Log on to the CLI via SSH.
2. Type "enable", enter the enable password.
3. Type "configure terminal" and press "Enter".
4. Type "management-services" and press "Enter", type "edit HTTPS-Console" and press "Enter".
5. Type "view" to display the list of configured cipher suites.
6. Type "attribute cipher-suite" followed by a space-delimited list of only cipher suites from step 5 which use FIPS compliant HMAC algorithms and press "Enter".
Verify only FIPS compliant HMAC algorithms are in use.
1. Log on to the CLI via SSH.
2. Type "show management services", press "Enter".
3. Ensure that the "Cipher Suite" attribute lists only cipher suites which use FIPS compliant HMAC algorithms.
If any cipher suites are listed that use non-FIPS compliant HMAC algorithms, this is a finding.
V-94711
False
SYMP-NM-000300
Verify only FIPS compliant HMAC algorithms are in use.
1. Log on to the CLI via SSH.
2. Type "show management services", press "Enter".
3. Ensure that the "Cipher Suite" attribute lists only cipher suites which use FIPS compliant HMAC algorithms.
If any cipher suites are listed that use non-FIPS compliant HMAC algorithms, this is a finding.
M
3517