Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-23828 | GEN007970 | SV-38965r1_rule | DCNR-1 | Medium |
Description |
---|
LDAP can be used to provide user authentication and account information, which are vital to system security. Cryptographic modules used by the system must be validated by the NIST CVMP as compliant with FIPS 140-2. Cryptography performed by unvalidated modules is viewed by NIST as providing no protection for the data. |
STIG | Date |
---|---|
Draft AIX Security Technical Implementation Guide | 2011-08-17 |
Check Text ( C-37918r1_chk ) |
---|
Determine if the system uses LDAP authentication. #grep LDAP /etc/security/user If no results are returned, this is not applicable. Determine if the system uses a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for protecting the LDAP connection. If it does not, this is a finding. |
Fix Text (F-33174r1_fix) |
---|
Configure the system to use a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for protecting the LDAP connection. |