Check: GEN000588
VMware ESX 3 Server:
GEN000588
(in version v1 r2)
Title
The system must use a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for generating system password hashes. (Cat II impact)
Discussion
Cryptographic modules used by the system must be validated by the NIST CVMP as compliant with FIPS 140-2. Cryptography performed by modules not validated is viewed by NIST as providing no protection for the data.
Check Content
Determine if the system uses a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for generating system password hashes. The NIST CVMP web site provides a list of validated modules and the required security policies for the compliant use of such modules. Verify the module is on this list and configured in accordance with the validated security policy. If the system does not use a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for generating system password hashes, this is a finding.
Fix Text
Configure the system to use a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for generating system password hashes.
Additional Identifiers
Rule ID: SV-28761r1_rule
Vulnerability ID: V-23825
Group Title: GEN000588
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001145 |
The organization employs, at a minimum, FIPS-validated cryptography to protect unclassified information. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |