Rule version BCAS-ND-001335 · STIG v1 · 2026-09-16
Legacy cryptographic protocols, such as TLS version 1.0 and 1.1, contain inherent design flaws and known vulnerabilities that allow attackers to decrypt or manipulate data in transit. To secure the system's communication channels and APIs (such as the ICAP interface), these nonsecure protocols must be explicitly disabled. The appliance must be configured to enforce only DoW-approved, secure protocols (TLS 1.2 and TLS 1.3) to ensure the confidentiality and integrity of all transmitted data.
Verify nonsecure TLS versions are disabled and secure TLS versions are enforced with the following steps:
1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICAP. 3. Under "TLS Settings", verify that "TLSv1" and "TLSv1.1" are not checked. 4. Verify that "TLSv1.2" and "TLSv1.3" are checked.
If either "TLSv1" or "TLSv1.1" are checked, or if the approved secure TLS versions are not enabled, this is a finding.
Configure the CAS to disable nonsecure TLS versions and enforce secure TLS versions with the following steps:
1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICAP. 3. Under "TLS Settings", uncheck "TLSv1" and "TLSv1.1" to disable the nonsecure protocols. 4. Check the boxes to enable "TLSv1.2" and "TLSv1.3". 5. Click "Save Settings".