Rule ID
SV-288248r1252947_rule
Version
V1R0.1
CCIs
FIPS 140-3 precludes the use of invalidated cryptography for the cryptographic protection of sensitive or valuable data within federal systems. Unvalidated cryptography is viewed by NIST as providing no protection to the information or data. In effect, the data would be considered unprotected plaintext. If the agency specifies that the information or data be cryptographically protected, then FIPS 140-3 is applicable. If cryptography is required, it must be validated. Cryptographic modules that have been approved for classified use may be used in lieu of modules that have been validated against the FIPS 140-3 standard. Provisioning of digital signatures pertains to certificate authority or Public Key Infrastructure (PKI)-type applications that generate certificates (e.g., OpenSSL, code signing applications, etc.); otherwise, this requirement is considered Not Applicable. The cryptographic module used must have at least one validated digital signature function. This validated hash algorithm must be used to generate digital signatures for all cryptographic security function within the product being evaluated. This requirement pertains to Zero Trust.
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses a FIPS-validated cryptographic module to provision digital signatures. If the application's cryptography mechanism does not use a FIPS-validated cryptographic module to provision digital signatures, this is a finding.
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use a FIPS-validated cryptographic module to provision digital signatures.