SV-239716r679258_rule
V-239716
SRG-APP-000014-WSR-000006
VCLD-67-000002
CAT I
10
Navigate to and open /etc/applmgmt/appliance/lighttpd.conf.
Add or reconfigure the following value:
ssl.cipher-list = "!aNULL:kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES"
At the command prompt, execute the following command:
# /opt/vmware/sbin/vami-lighttpd -p -f /opt/vmware/etc/lighttpd/lighttpd.conf|grep "ssl.cipher-list"
Expected result:
ssl.cipher-list = "!aNULL:kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES"
If the output does not match the expected result, this is a finding.
V-239716
False
VCLD-67-000002
At the command prompt, execute the following command:
# /opt/vmware/sbin/vami-lighttpd -p -f /opt/vmware/etc/lighttpd/lighttpd.conf|grep "ssl.cipher-list"
Expected result:
ssl.cipher-list = "!aNULL:kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES"
If the output does not match the expected result, this is a finding.
M
5335