4.1.6 Ensure awareness of TLS 1.3 new Diffie-Hellman parameters

Information

This control is not applicable to environments exclusively using TLS 1.3.

The TLS 1.3 protocol (RFC 8446) deprecates the use of custom finite-field Diffie-Hellman (DHE) groups, which were configured via the ssl_dhparam directive in NGINX. Instead, TLS 1.3 exclusively uses a set of pre-defined, standardized, and secure elliptic curve (ECDHE) and finite-field (FFDHE) groups for its key exchange mechanism. This design eliminates the risk associated with weak or misconfigured custom DH parameters. As such, the ssl_dhparam directive has no effect in a TLS 1.3-only configuration.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

No remediation is necessary. Ensure ssl_protocols TLSv1.3; is set. The ssl_dhparam directive should be removed as it is obsolete.

Impact:

None for a TLS 1.3-only configuration.

See Also

https://workbench.cisecurity.org/benchmarks/18528

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 25a85992eefe4e8c68eba432968c53f053bbb7d27d30e623a753ffa814d6a549