SV-283387r1194855_rule
V-283387
SRG-APP-000179-NDM-000265
ASMP-ND-000600
CAT I
10
Warning: Enabling FIPS mode requires restarting all system management interfaces, which will terminate all existing connections including this one.
Set the communications encryption module into FIPS mode:
cli% controlsecurity fips enable
Verify the status of the FIPS communication library with the following command:
cli% controlsecurity fips status
FIPS mode: Enabled
Service Status
AUTHN Enabled
CIM Disabled
CLI Enabled
EKM Enabled
LDAP Enabled
QW Enabled
RDA Enabled
SC CONNECTOR Disabled
SNMP Enabled
SSH Enabled
SYSLOG Enabled
VASA Enabled
WSAPI Enabled
If the line "FIPS Mode:" is not "Enabled", this is a finding.
If any of the service lines for "CLI", "EKM", "LDAP", "SNMP", "SSH", or "SYSLOG" are "Disabled", this is a finding.
If CIM, VASA, or WSAPI are "Disabled", and the services are enabled, this is a finding.
V-283387
False
ASMP-ND-000600
Verify the status of the FIPS communication library with the following command:
cli% controlsecurity fips status
FIPS mode: Enabled
Service Status
AUTHN Enabled
CIM Disabled
CLI Enabled
EKM Enabled
LDAP Enabled
QW Enabled
RDA Enabled
SC CONNECTOR Disabled
SNMP Enabled
SSH Enabled
SYSLOG Enabled
VASA Enabled
WSAPI Enabled
If the line "FIPS Mode:" is not "Enabled", this is a finding.
If any of the service lines for "CLI", "EKM", "LDAP", "SNMP", "SSH", or "SYSLOG" are "Disabled", this is a finding.
If CIM, VASA, or WSAPI are "Disabled", and the services are enabled, this is a finding.
M
5742