AOS must use FIPS 140-2/140-3 approved algorithms for authentication to a cryptographic module.
DISA Rule
SV-266940r1039841_rule
Vulnerability Number
V-266940
Group Title
SRG-APP-000179-NDM-000265
Rule Version
ARBA-ND-000265
Severity
CAT I
CCI(s)
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-001188 - Generate a unique session identifier for each session with organization-defined randomness requirements.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
- CCI-003123 - Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
Weight
10
Fix Recommendation
Configure AOS with the following commands:
configure terminal
fips enable
write memory
reload
Check Contents
Verify the AOS configuration with the following command:
show fips
If "FIPS settings: Mode Enabled" is not returned, this is a finding.
Vulnerability Number
V-266940
Documentable
False
Rule Version
ARBA-ND-000265
Severity Override Guidance
Verify the AOS configuration with the following command:
show fips
If "FIPS settings: Mode Enabled" is not returned, this is a finding.
Check Content Reference
M
Target Key
5648