Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • SRG-NET-000164-ALG-000100

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC when used for TLS encryption and decryption must validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation.

    &lt;VulnDiscussion&gt;A certificate's certification path is the path from the end entity certificate to a trusted root certification authority (CA)...
    Rule Medium Severity
  • SRG-NET-000202-ALG-000124

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC must not have any unnecessary or unapproved virtual servers configured.

    &lt;VulnDiscussion&gt;A deny-all, permit-by-exception network communications traffic policy ensures that only those connections which are essential...
    Rule Medium Severity
  • SRG-NET-000273-ALG-000129

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC, when used to load balance web applications, must strip HTTP response headers.

    &lt;VulnDiscussion&gt;Providing too much information in error messages risks compromising the data and security of the application and system. HTTP...
    Rule Medium Severity
  • SRG-NET-000273-ALG-000129

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC, when used to load balance web applications, must replace response codes.

    &lt;VulnDiscussion&gt;Providing too much information in error messages risks compromising the data and security of the application and system. HTTP...
    Rule Medium Severity
  • SRG-NET-000318-ALG-000014

    <GroupDescription></GroupDescription>
    Group
  • To protect against data mining, the A10 Networks ADC must detect and prevent SQL and other code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.

    &lt;VulnDiscussion&gt;Data mining is the analysis of large quantities of data to discover patterns and is used in intelligence gathering. Failure t...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules