STIGQter STIGQter: STIG Summary: CA API Gateway ALG Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 28 Apr 2017:

The CA API Gateway that stores secret or private keys must use FIPS-approved key management technology and processes in the production and control of private/secret cryptographic keys.

DISA Rule

SV-85931r1_rule

Vulnerability Number

V-71307

Group Title

SRG-NET-000062-ALG-000092

Rule Version

CAGW-GW-000180

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Refer to the “CA API Management Documentation Wiki" at https://wiki.ca.com/display/GATEWAY90/CA+API+Gateway+Home for directions on configuring the CA API Gateway to use a SafeNet Luna HSM for secure private key storage.

Check Contents

Verify an HSM, such as the SafeNet Luna HSM, is currently storing Private Keys.

If an HSM is not present, this is a finding.

Vulnerability Number

V-71307

Documentable

False

Rule Version

CAGW-GW-000180

Severity Override Guidance

Verify an HSM, such as the SafeNet Luna HSM, is currently storing Private Keys.

If an HSM is not present, this is a finding.

Check Content Reference

M

Target Key

3049

Comments