SV-251237r961116_rule
V-251237
SRG-APP-000223-DB-000168
RD6X-00-010300
CAT II
10
To configure TLS and configure only organizationally defined CA-signed certificates, refer to the following document:
https://docs.redislabs.com/latest/rs/administering/cluster-operations/updating-certificates/
By default, each cluster node has a different set of self-signed certificates. These certificates can be replaced with a DoD-acceptable certificate, preferably a certificate issued by an intermediate certificate authority (CA).
For security reasons, Redis Enterprise only supports the TLS protocol. Therefore, verify that the Redis client or secured tunnel solution is TLS v1.2 or above.
Run the following commands and verify that certificates are present:
# cd /etc/opt/redislabs
# ls
Verify the proxy_cert.pem file is present.
If no certificates are present, this is a finding.
V-251237
False
RD6X-00-010300
By default, each cluster node has a different set of self-signed certificates. These certificates can be replaced with a DoD-acceptable certificate, preferably a certificate issued by an intermediate certificate authority (CA).
For security reasons, Redis Enterprise only supports the TLS protocol. Therefore, verify that the Redis client or secured tunnel solution is TLS v1.2 or above.
Run the following commands and verify that certificates are present:
# cd /etc/opt/redislabs
# ls
Verify the proxy_cert.pem file is present.
If no certificates are present, this is a finding.
M
5443