The Ivanti EPMM server must use FIPS-validated SHA-2 or higher hash function to protect the integrity of keyed-hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, and hash-only applications.
DISA Rule
SV-251413r1004734_rule
Vulnerability Number
V-251413
Group Title
SRG-APP-000179-UEM-000110
Rule Version
IMIC-11-006400
Severity
CAT I
CCI(s)
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
Weight
10
Fix Recommendation
Configure Core to be in FIPS mode.
ssh to command line console of the Core. Enable >> show fips. Configure fips >> reload.
Check Contents
Verify MobileIron Core is in FIPS mode.
ssh to command line console of the Core. Enable >> show fips. Verify FIPS mode is configured.
If FIPS mode is not configured, this is a finding.
Vulnerability Number
V-251413
Documentable
False
Rule Version
IMIC-11-006400
Severity Override Guidance
Verify MobileIron Core is in FIPS mode.
ssh to command line console of the Core. Enable >> show fips. Verify FIPS mode is configured.
If FIPS mode is not configured, this is a finding.
Check Content Reference
M
Target Key
5445