SV-274783r1143932_rule
V-274783
SRG-APP-000630
SRG-APP-000630-API-001375
CAT II
10
Build or configure the API to utilize a FIPS-validated cryptographic module to provision digital signatures.
Verify the API must use a FIPS-validated cryptographic module to provision digital signatures for tokens.
Authentication to microservices: APIs that have access to sensitive data must not be done simply by using API keys. Access to such APIs must require authentication tokens that have either been digitally signed (e.g., client credentials grant) or verified with an authoritative source.
Services may require either single-use tokens or short-lived tokens (tokens that expire after a short time period) to limit the damage a compromised token can cause.
If the API does not use a FIPS validated cryptographic module to provision signatures for tokens, this is a finding.
V-274783
False
SRG-APP-000630-API-001375
Verify the API must use a FIPS-validated cryptographic module to provision digital signatures for tokens.
Authentication to microservices: APIs that have access to sensitive data must not be done simply by using API keys. Access to such APIs must require authentication tokens that have either been digitally signed (e.g., client credentials grant) or verified with an authoritative source.
Services may require either single-use tokens or short-lived tokens (tokens that expire after a short time period) to limit the damage a compromised token can cause.
If the API does not use a FIPS validated cryptographic module to provision signatures for tokens, this is a finding.
M
5703