SV-91125r1_rule
V-76429
SRG-NET-000510-ALG-000040
AKSD-WF-000023
CAT II
10
Configure Kona Site Defender to only allow NIST FIPS-validated cryptography for digital signatures:
Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
Confirm Kona Site Defender only allows NIST SP 800-52 TLS settings:
1. Navigate to the Qualys SSL Scanner: https://www.ssllabs.com/ssltest/analyze.html
2. Enter into the scanner the Hostname being tested.
3. Under the "Certificate" section, verify that the "Signature algorithm" is restricted to NIST FIPS-validated cryptography for digital signatures as defined at https://www.nist.gov/publications/guidelines-selection-configuration-and-use-transport-layer-security-tls-implementations?pub_id=915295.
If the signature algorithm include non-NIST FIPS-validated cryptography, this is a finding.
V-76429
False
AKSD-WF-000023
Confirm Kona Site Defender only allows NIST SP 800-52 TLS settings:
1. Navigate to the Qualys SSL Scanner: https://www.ssllabs.com/ssltest/analyze.html
2. Enter into the scanner the Hostname being tested.
3. Under the "Certificate" section, verify that the "Signature algorithm" is restricted to NIST FIPS-validated cryptography for digital signatures as defined at https://www.nist.gov/publications/guidelines-selection-configuration-and-use-transport-layer-security-tls-implementations?pub_id=915295.
If the signature algorithm include non-NIST FIPS-validated cryptography, this is a finding.
M
3165