Security Policy: Difference between revisions

Jump to navigation Jump to search
m
Line 73: Line 73:
| 13 || The FIPS PUB 140-2 cryptographic module shall require the user to establish a password (for the NSS user role) in order for subsequent authentications to be enforced.
| 13 || The FIPS PUB 140-2 cryptographic module shall require the user to establish a password (for the NSS user role) in order for subsequent authentications to be enforced.
|-
|-
| 14 || A known password check string, encrypted with a Triple-DES key derived from the password, shall be stored in the private key database (cert3.db) in secondary storage. '''Note:''' password-based encryption is not FIPS Approved.
| 14 || A known password check string, encrypted with a Triple-DES key derived from the password, shall be stored in the private key database (key3.db) in secondary storage. '''Note:''' password-based encryption is not FIPS Approved.
|-
|-
| 15 || Once a password has been established for the FIPS PUB 140-2 cryptographic module, it shall only allow the user to use the private services if and only if the user successfully authenticates to the FIPS PUB 140-2 cryptographic module.
| 15 || Once a password has been established for the FIPS PUB 140-2 cryptographic module, it shall only allow the user to use the private services if and only if the user successfully authenticates to the FIPS PUB 140-2 cryptographic module.
198

edits

Navigation menu