SV-225223r615940_rule
V-225223
SRG-APP-000175
APPNET0031
CAT II
10
Use regedit to remove the values stored in Windows registry key HKLM\Software\Microsoft\StrongName\Verification. There should be no assemblies or hash values listed under this registry key.
All assemblies must require strong name verification in a production environment.
Strong name assemblies that do not require verification in a development or test environment must have documented approvals from the IAO.
Use regedit to review the Windows registry key
HKLM\Software\Microsoft\StrongName\Verification.
There should be no assemblies or hash values listed under this registry key. If the StrongName\Verification key does not exist, this is not a finding.
If there are assemblies or hash values listed in this key, each value represents a distinct application assembly that does not have the application strong name verified.
If any assemblies are listed as omitting strong name verification in a production environment, this is a finding.
If any assemblies are listed as omitting strong name verification in a development or test environment and the IAO has not provided documented approvals, this is a finding.
V-225223
False
APPNET0031
Use regedit to review the Windows registry key
HKLM\Software\Microsoft\StrongName\Verification.
There should be no assemblies or hash values listed under this registry key. If the StrongName\Verification key does not exist, this is not a finding.
If there are assemblies or hash values listed in this key, each value represents a distinct application assembly that does not have the application strong name verified.
If any assemblies are listed as omitting strong name verification in a production environment, this is a finding.
If any assemblies are listed as omitting strong name verification in a development or test environment and the IAO has not provided documented approvals, this is a finding.
M
4213