SV-274603r1143636_rule
V-274603
SRG-APP-000224
SRG-APP-000224-API-000475
CAT II
10
This requirement is applicable only to devices that use a web interface for device management.
Build or configure the API to use FIPS 140-3-validated cryptographic modules when the API implements RNGs for key generation.
This requirement is applicable only to devices that use a web interface for device management.
Verify the API keys are securely generated using a FIPS-validated RNG.
Review the API documentation and interview the API administrator.
Identify the cryptographic modules utilized by the API for key generation.
Identify the cryptographic service provider utilized by the API and reference the NIST validation website to ensure the algorithms utilized are approved: https://csrc.nist.gov/projects/cryptographic-module-validation-program.
If the API does not use a FIPS 140-3-approved RNG, this is a finding.
V-274603
False
SRG-APP-000224-API-000475
This requirement is applicable only to devices that use a web interface for device management.
Verify the API keys are securely generated using a FIPS-validated RNG.
Review the API documentation and interview the API administrator.
Identify the cryptographic modules utilized by the API for key generation.
Identify the cryptographic service provider utilized by the API and reference the NIST validation website to ensure the algorithms utilized are approved: https://csrc.nist.gov/projects/cryptographic-module-validation-program.
If the API does not use a FIPS 140-3-approved RNG, this is a finding.
M
5703