SV-93593r1_rule
V-78887
SRG-OS-000120-GPOS-00061
IBMZ-VM-000660
CAT I
10
Configure the SSL DTCPARMS file with a :PARMS tag that includes “VMSSL” command.
Configure the “VMSSL” command to MODE FIPS-140-2, either by including the FIPS operand or by setting the “MODE” operand to FIPS-140-2.
Include the PROTOcol operands for TLSV1_2.
Determine and examine the “DTCPARMS” file for each SSL server pool.
If the "VMSSL" command is not included in a :PARMS tag, this is a finding.
If the “VMSSL” command is not configured as follows, this is a finding.
FIPS (Operand FIPS is equivalent to setting MODE FIPS-140-2.)
MODE FIPS-140-2 (Operand MODE FIPS-140-2 is equivalent to setting operand FIPS.)
PROTOcol TLSV1_2
V-78887
False
IBMZ-VM-000660
Determine and examine the “DTCPARMS” file for each SSL server pool.
If the "VMSSL" command is not included in a :PARMS tag, this is a finding.
If the “VMSSL” command is not configured as follows, this is a finding.
FIPS (Operand FIPS is equivalent to setting MODE FIPS-140-2.)
MODE FIPS-140-2 (Operand MODE FIPS-140-2 is equivalent to setting operand FIPS.)
PROTOcol TLSV1_2
M
3211