Rule ID
SV-288146r1252023_rule
Version
V1R0.1
Identity assertions and access tokens are typically digitally signed. The private keys used to sign these assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.
Review the application documentation and deployed configuration to determine whether the application generates, manages, and protects from disclosure and misuse the cryptographic keys that protect access tokens. If the application does not generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens, this is a finding.
Configure the application to generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.