UCF STIG Viewer Logo

The operating system must employ cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.


Overview

Finding ID Version Rule ID IA Controls Severity
V-220008 SOL-11.1-060110 SV-220008r603268_rule Medium
Description
Ensuring that transmitted information does not become disclosed to unauthorized entities requires the operating system take feasible measures to employ transmission layer security. This requirement applies to communications across internal and external networks.
STIG Date
Solaris 11 X86 Security Technical Implementation Guide 2021-11-23

Details

Check Text ( C-21718r372895_chk )
All remote sessions must be conducted via encrypted services and ports.

Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix Text (F-21717r372896_fix)
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.