SV-77467r1_rule
V-62977
SRG-APP-000179-NDM-000265
RICX-DM-000130
CAT II
10
Configure RiOS to be licenses to use FIPS 140-2 cryptographic modules.
Navigate to the device CLI
Type: enable
Type: config t
Type: license install <license-string>
Type: web ssl cipher TLSv1.2+FIPS:kRSA+FIPS:!eNULL:!aNULL
Type: write memory
Verify license installation
Type: show licenses
Type: show web ssl cipher
Verify that RiOS is licensed to use FIPS 140-2 cryptographic modules.
Navigate to the device CLI
Type: enable
Type: config t
Type: show licenses
Verify installation of a FIPS License
Type: show web ssl cipher
Verify that the web ssl cipher string is:
"TLSv1.2+FIPS:kRSA+FIPS:!eNULL:!aNULL"
If a FIPS license is not present and the web ssl cipher string is not set properly, this is a finding.
V-62977
False
RICX-DM-000130
Verify that RiOS is licensed to use FIPS 140-2 cryptographic modules.
Navigate to the device CLI
Type: enable
Type: config t
Type: show licenses
Verify installation of a FIPS License
Type: show web ssl cipher
Verify that the web ssl cipher string is:
"TLSv1.2+FIPS:kRSA+FIPS:!eNULL:!aNULL"
If a FIPS license is not present and the web ssl cipher string is not set properly, this is a finding.
M
2931