SV-86087r1_rule
V-71463
SRG-NET-000400-ALG-000097
CAGW-GW-000830
CAT II
10
Open the CA API Gateway - Policy Manager and open each of the Registered Services that requires authentication passwords to be protected and that does not include the "Require SSL or TLS Transport" Assertion.
Add the "Require SSL or TLS Transport" Assertion and click the "Save and Activate" button to activate the changes to the policy.
Open the CA API Gateway - Policy Manager and open each of the Registered Services that requires the authentication passwords to be protected.
Verify the "Require SSL or TLS Transport" Assertion is present.
If it is not, this is a finding.
V-71463
False
CAGW-GW-000830
Open the CA API Gateway - Policy Manager and open each of the Registered Services that requires the authentication passwords to be protected.
Verify the "Require SSL or TLS Transport" Assertion is present.
If it is not, this is a finding.
M
3049