UCF STIG Viewer Logo

vRA must enable FIPS Mode.


Overview

Finding ID Version Rule ID IA Controls Severity
V-89125 VRAU-AP-000265 SV-99775r1_rule High
Description
Encryption is only as good as the encryption modules utilized. Unapproved cryptographic module algorithms cannot be verified and cannot be relied upon to provide confidentiality or integrity, and DoD data may be compromised due to weak algorithms. The use of TLS provides confidentiality of data in transit between the application server and client. FIPS 140-2 approved TLS versions include TLS V1.0 or greater. TLS must be enabled and non-FIPS-approved SSL versions must be disabled. NIST SP 800-52 specifies the preferred configurations for government systems.
STIG Date
VMware Automation 7.x Application Security Technical Implementation Guide 2018-10-12

Details

Check Text ( C-88817r2_chk )
Check that FIPS mode is enabled in the vRealize Automation virtual appliance management interface with the following steps:

1. Log on to the vRealize Automation virtual appliance management interface (vAMI): https://vrealize-automation-appliance-FQDN:5480
2. Select vRA Settings >> Host Settings.
3. Review the button under the Actions heading on the upper right to confirm that "enable FIPS" is selected.

If "enable FIPS" is not selected, this is a finding.

Alternately, check that FIPS mode is enabled in the command line using the following steps:

1. Log on to the console as root.
2. Run the command: vcac-vami fips status

If FIPS is not enabled, this is a finding.
Fix Text (F-95867r2_fix)
FIPS mode in the vRealize Automation virtual appliance management interface can be enabled with the following steps:

1. Log on to the vRealize Automation virtual appliance management interface (vAMI): https://vrealize-automation-appliance-FQDN:5480
2. Select vRA Settings >> Host Settings.
3. Click the button under the "Actions" heading on the upper right to enable or disable FIPS.
4. Click "Yes" to restart the vRealize Automation appliance.

Alternately, FIPS mode can be enabled in the command line using the following steps:
1. Log on to the console as root.
2. Run the command: vcac-vami fips enable