The DataPower Gateway must protect the authenticity of communications sessions.

From IBM DataPower ALG Security Technical Implementation Guide

Part of SRG-NET-000230-ALG-000113

Associated with: CCI-001184

SV-79723r1_rule The DataPower Gateway must protect the authenticity of communications sessions.

Vulnerability discussion

Authenticity protection provides protection against man-in-the-middle attacks/session hijacking and the insertion of false information into sessions.This requirement focuses on communications protection for the application session rather than for the network packet and establishes grounds for confidence at both ends of communications sessions in ongoing identities of other parties and in the validity of information transmitted. Depending on the required degree of confidentiality and integrity, web services/SOA will require the use of mutual authentication (two-way/bidirectional).

Check content

Using the WebGUI at Objects >> Crypto Configuration >> SSL Client Profile and SSL Server Profile. Select the profiles that are configured for the application session requiring mutual authentication. Confirm that the correct protocol and cipher parameters are set and that the correct identification and validation credentials are specified. If these items are not configured, this is a finding.

Fix text

Using the WebGUI at Objects >> Crypto Configuration >> SSL Client Profile and SSL Server Profile. Create a client and server profile for the application session requiring mutual authentication. Specify the correct protocol and cipher parameters and the correct identification and validation credentials.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer