SYMP-AG-000450 - Symantec ProxySG providing forward proxy encryption intermediary services must use NIST FIPS-validated cryptography to implement encryption services. - Source

Information

Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. The network element must implement cryptographic modules adhering to the higher standards approved by the Federal government since this provides assurance they have been tested and validated.

This requirement applies only to ALGs that provide encryption intermediary services (e.g., HTTPS, TLS, or DNSSEC).

Solution

Configure TLS intermediary services to comply with NIST FIPS-validated cryptography.

1. Log on to the Web Management Console.
2. Click Configuration >> Visual Policy Manager.
3. Click 'Launch'. While in the Visual Policy Manager, click Policy >> Add SSL Access Layer.
4. Right-click the 'Source' field of the existing rule and select 'Set'. Click 'New' and select 'Combined Source Object'.
5. Click 'New' and select 'Client Negotiated Cipher'. Select all ciphers that should be permitted and click 'OK'.
6. Click the upper 'Add' button and click the 'Negate' checkbox.
7. Click 'New' and select 'Client Negotiated SSL Version'. Select all NIST FIPS-validated SSL versions that should be permitted and click 'OK'.
8. Click the upper 'Add' button.
9. Click 'OK' and then 'OK' again.
10. Repeat steps 4-9 for the 'Destination' field using the 'Server Negotiated Cipher' and 'Server Negotiated SSL Version' objects.
11. Right-click the 'Action' field of the rule, click 'Set', and select 'Deny'.
12. Click File >> Install Policy on SG Appliance.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SYM_ProxySG_Y20M04_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-002450, Rule-ID|SV-104257r1_rule, STIG-ID|SYMP-AG-000450, Vuln-ID|V-94303

Plugin: BlueCoat

Control ID: 294a7f0cbb19837815214c1dcef122601fc46821c5ab4352b940c6bbb4054a94