UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The designer shall ensure messages are encrypted when the SessionIndex is tied to privacy data.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22031 APP3950 SV-25357r1_rule ECNK-1 Medium
Description
When the SessionIndex is tied to privacy data (e.g., attributes containing privacy data) the message should be encrypted. If the message is not encrypted there is the possibility of compromise of privacy data.
STIG Date
Application Security and Development Checklist 2014-04-03

Details

Check Text ( C-27029r1_chk )
Examine the contents of a SOAP message using a SessionIndex in the SAML element AuthnStatement. Verify the information which is tied to the SessionIndex.

If the SessionIndex is tied to privacy information, and it is not encrypted, it is a finding.
Fix Text (F-23095r1_fix)
Encrypt messages when the SessionIndex is tied to privacy data.