The Riverbed NetProfiler must be configured to implement cryptographic mechanisms using a FIPS 140-2/140-3 validated algorithm to protect the confidentiality and integrity of all cryptographic functions.
DISA Rule
SV-256090r1015804_rule
Vulnerability Number
V-256090
Group Title
SRG-APP-000412-NDM-000331
Rule Version
RINP-DM-000054
Severity
CAT I
CCI(s)
- CCI-004062 - For password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.
- CCI-000197 - For password-based authentication, transmit passwords only cryptographically-protected channels.
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-001188 - Generate a unique session identifier for each session with organization-defined randomness requirements.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
- CCI-003123 - Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
Weight
10
Fix Recommendation
Go to Administration >> Appliance Security >> Security Compliance.
Under "Operational Modes", enable "FIPS 140-2 Compatible Cryptography".
NOTE: Configuring FIPS mode is the required DOD configuration. However, the severity of this requirement can be decreased to a CAT III if the alternative manual configuration is used to configure individual protocols because this allows non-FIPS validated algorithms to be used for some functions.
Check Contents
Go to Administration >> Appliance Security >> Security Compliance.
Check under "Operational Modes".
If "FIPS 140-2 Compatible Cryptography" is not enabled, this is a finding.
Vulnerability Number
V-256090
Documentable
False
Rule Version
RINP-DM-000054
Severity Override Guidance
Go to Administration >> Appliance Security >> Security Compliance.
Check under "Operational Modes".
If "FIPS 140-2 Compatible Cryptography" is not enabled, this is a finding.
Check Content Reference
M
Target Key
5514