SV-279095r1171617_rule
V-279095
SRG-APP-000440-AS-000167
APAS-CF-000885
CAT I
10
Configure JVM Arguments for Crypto.
1. From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.
2. Amend JVM arguments with "-Dcoldfusion.enablefipscrypto=true".
3. Click "Submit Changes".
4. If not using Enterprise Edition or cryptographic mechanisms are not available, reinstall with Enterprise Edition.
Verify JVM Arguments for Crypto.
1. From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.
If the JVM argument contains "-Dcoldfusion.enablefipscrypto=false" or
"-Dcoldfusion.enablefipscrypto" is missing, this is a finding.
2. Observe the ColdFusion edition at the top of the Administrator Console.
If the edition is "Standard", this is a finding.
V-279095
False
APAS-CF-000885
Verify JVM Arguments for Crypto.
1. From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.
If the JVM argument contains "-Dcoldfusion.enablefipscrypto=false" or
"-Dcoldfusion.enablefipscrypto" is missing, this is a finding.
2. Observe the ColdFusion edition at the top of the Administrator Console.
If the edition is "Standard", this is a finding.
M
5724