SV-79599r1_rule
V-65109
SRG-APP-000224-NDM-000270
WSDP-NM-000072
CAT II
10
From the DataPower command line, enter "use-fips on" to configure DataPower to generate unique session identifiers using a FIPS 140-2 approved random number generator. From the web interface, use "Set Cryptographic Mode" (Administration >> Miscellaneous >> Crypto Tools, Set Cryptographic Mode tab) to set the appliance to "FIPS 140-2 Level 1" mode.
This will achieve NIST SP800-131a compliance.
From the web interface for DataPower device management, verify that the DataPower Gateway Cryptographic Mode is Set to FIPS 140-2 Level 1; Status >> Crypto >> Cryptographic Mode Status.
If it is not set to FIPS 140-2, this is a finding.
Then, verify that the session identifiers (TIDs) in the System Log are random: Status >> View Logs >> Systems Logs.
If they are not random, this is a finding.
V-65109
False
WSDP-NM-000072
From the web interface for DataPower device management, verify that the DataPower Gateway Cryptographic Mode is Set to FIPS 140-2 Level 1; Status >> Crypto >> Cryptographic Mode Status.
If it is not set to FIPS 140-2, this is a finding.
Then, verify that the session identifiers (TIDs) in the System Log are random: Status >> View Logs >> Systems Logs.
If they are not random, this is a finding.
M
2861