STIGQter STIGQter: STIG Summary: IBM DataPower ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Jan 2016:

The DataPower Gateway that provides intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52.

DISA Rule

SV-79695r1_rule

Vulnerability Number

V-65205

Group Title

SRG-NET-000062-ALG-000150

Rule Version

WSDP-AG-000018

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The implementer will configure an "SSL Server Profile" to be used for SSL negotiation of a given service.

In the search field, enter "SSL Server Profile" >> Select "SSL Server Profile" from the results >> Click "Add" >> Configure the SSL Server Profile, providing a logical object name and appropriate selection of settings (depending on what type of SSL connection is to be implemented - forward, reverse, mutual) >> Protocols to be enabled include TLS 1.1 and 1.2 (both are enabled by default).

Check Contents

In the search field, enter "SSL Server Profile" >> Select "SSL Server Profile" from the results >> Click the name of the SSL Server Profile object to be inspected >> Confirm that the TLS 1.1 and TLS 1.2 protocol options are checked.

If they are not checked, this is a finding.

Vulnerability Number

V-65205

Documentable

False

Rule Version

WSDP-AG-000018

Severity Override Guidance

In the search field, enter "SSL Server Profile" >> Select "SSL Server Profile" from the results >> Click the name of the SSL Server Profile object to be inspected >> Confirm that the TLS 1.1 and TLS 1.2 protocol options are checked.

If they are not checked, this is a finding.

Check Content Reference

M

Target Key

2859

Comments