The WebSphere Application Server must utilize FIPS 140-2-approved encryption modules when authenticating users and processes.
DISA Rule
SV-255875r1193273_rule
Vulnerability Number
V-255875
Group Title
SRG-APP-000179-AS-000129
Rule Version
WBSP-AS-001290
Severity
CAT II
CCI(s)
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-001188 - Generate a unique session identifier for each session with organization-defined randomness requirements.
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
- CCI-002421 - Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission.
- CCI-002422 - Maintain the confidentiality and/or integrity of information during reception.
- CCI-002450 - Implement organization-defined types of cryptography for each specified cryptography use.
Weight
10
Fix Recommendation
From administrative console, click Security >> SSL certificate and key management >> Manage FIPS.
Check "Enable FIPS 140-2".
Click "Save".
Synchronize with the nodes.
Restart all the JVMs.
Check Contents
Note: If FIPS 140-3 is configured in WBSP-AS-001770, this is not applicable.
From the administrative console, click Security >> SSL certificate and key management >> Manage FIPS.
If "Enable FIPS 140-2" is not selected, this is a finding.
Vulnerability Number
V-255875
Documentable
False
Rule Version
WBSP-AS-001290
Severity Override Guidance
Note: If FIPS 140-3 is configured in WBSP-AS-001770, this is not applicable.
From the administrative console, click Security >> SSL certificate and key management >> Manage FIPS.
If "Enable FIPS 140-2" is not selected, this is a finding.
Check Content Reference
M
Target Key
5510