SV-99817r1_rule
V-89167
SRG-APP-000179-WSR-000111
VRAU-HA-000210
CAT II
10
Navigate to and open the following files:
/etc/haproxy/conf.d/30-vro-config.cfg
/etc/haproxy/conf.d/20-vcac.cfg
Navigate to the frontend section in each file.
Configure the bind keyword file with this cipher list:
'FIPS: +3DES:!aNULL'
At the command prompt, execute the following command:
grep -E 'bind.*ssl' /etc/haproxy/conf.d/30-vro-config.cfg /etc/haproxy/conf.d/20-vcac.cfg
If the return value for SSL cipher list is not set to "FIPS: +3DES:!aNULL", this is a finding.
V-89167
False
VRAU-HA-000210
At the command prompt, execute the following command:
grep -E 'bind.*ssl' /etc/haproxy/conf.d/30-vro-config.cfg /etc/haproxy/conf.d/20-vcac.cfg
If the return value for SSL cipher list is not set to "FIPS: +3DES:!aNULL", this is a finding.
M
3455