Check: GEN007970
VMware ESX 3 Server:
GEN007970
(in version v1 r2)
Title
If the system is using LDAP for authentication or account information, the system must use a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for protecting the LDAP connection. (Cat II impact)
Discussion
LDAP can be used to provide user authentication and account information, which are vital to system security. Cryptographic modules used by the system must be validated by the NIST CVMP as compliant with FIPS 140-2. Cryptography performed by modules not validated is viewed by NIST as providing no protection for the data.
Check Content
Determine if the system uses NSS LDAP. If it does not, this is not applicable. Determine if the system uses a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for protecting the NSS LDAP connection. If it does not, this is a finding.
Fix Text
Configure the system to use a FIPS 140-2 validated cryptographic module (operating in FIPS mode) for protecting the NSS LDAP connection.
Additional Identifiers
Rule ID: SV-28764r1_rule
Vulnerability ID: V-23828
Group Title: GEN007970
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001145 |
The organization employs, at a minimum, FIPS-validated cryptography to protect unclassified information. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |