SV-85993r1_rule
V-71369
SRG-NET-000230-ALG-000113
CAGW-GW-000400
CAT II
10
Open the CA API Gateway - Policy Manager and double-click any of the Registered Services that do not have the "Require SSL or TLS Transport with Client Certificate Authentication" Assertion.
Optionally, if a Global Policy has been set, double-click that policy to inspect the contents.
Add the "Require SSL or TLS Transport with Client Certificate Authentication" Assertion to the policy and click "Save and Activate".
Open the CA API Gateway - Policy Manager and double-click any of the Registered Services that require the protection of communications sessions or mutual authentication.
Optionally, if a Global Policy has been set, double-click that policy to inspect the contents.
If the "Require SSL or TLS Transport with Client Certificate Authentication" Assertion is not present, this is a finding.
V-71369
False
CAGW-GW-000400
Open the CA API Gateway - Policy Manager and double-click any of the Registered Services that require the protection of communications sessions or mutual authentication.
Optionally, if a Global Policy has been set, double-click that policy to inspect the contents.
If the "Require SSL or TLS Transport with Client Certificate Authentication" Assertion is not present, this is a finding.
M
3049