Cisco IPS4345 Manual de usuario Pagina 32

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 61
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 31
Cisco Intrusion Prevention System Security Target
5.2.2.8 FCS_RBG_EXT.1 Extended: Cryptographic Operation (Random Bit Generation)
FCS_RBG_EXT.1.1 The TSF shall perform all random bit generation (RBG) services in
accordance with NIST Special Publication 800-90 using CTR_DRBG (AES) seeded by an
entropy source that accumulated entropy from a software-based noise source..
FCS_RBG_EXT.1.2 The deterministic RBG shall be seeded with a minimum of 256 bits of
entropy at least equal to the greatest bit length of the keys and authorization factors that it will
generate.
5.2.2.9 FCS_SSH_EXT.1 Explicit: SSH
FCS_SSH_EXT.1.1 The TSF shall implement the SSH protocol that complies with RFCs 4251,
4252, 4253, and 4254.
FCS_SSH_EXT.1.2 The TSF shall ensure that the SSH protocol implementation supports the
following authentication methods as described in RFC 4252: public key-based, password-based.
FCS_SSH_EXT.1.3 The TSF shall ensure that, as described in RFC 4253, packets greater than
[65,535] bytes in an SSH transport connection are dropped.
FCS_SSH_EXT.1.4 The TSF shall ensure that the SSH transport implementation uses the
following encryption algorithms: AES-CBC-128, AES-CBC-256, no other algorithms.
FCS_SSH_EXT.1.5 The TSF shall ensure that the SSH transport implementation uses
SSH_RSA and no other public key algorithms as its public key algorithm(s).
FCS_SSH_EXT.1.6 The TSF shall ensure that data integrity algorithms used in SSH transport
connection is hmac-sha1, hmac-sha1-96, hmac-md5, hmac-md5-96.
FCS_SSH_EXT.1.7 The TSF shall ensure that diffie-hellman-group14-sha1 is the only allowed
key exchange method used for the SSH protocol.
5.2.2.10 FCS_TLS_EXT.1 Explicit: TLS
FCS_TLS_EXT.1.1 The TSF shall implement one or more of the following protocols [TLS 1.0
(RFC 2246) TLS 1.1 (RFC 4346), and TLS 1.2 (RFC 5246)] supporting the following
ciphersuites:
Mandatory Ciphersuites:
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_DHE_RSA_WITH_AES_128_CBC_SHA
TLS_DHE_RSA_WITH_AES_256_CBC_SHA
Vista de pagina 31
1 2 ... 27 28 29 30 31 32 33 34 35 36 37 ... 60 61

Comentarios a estos manuales

Sin comentarios