5.03 OAS - 'Encryption Type - sqlnet.encryption_client = (ACCEPTED|REQUESTED|REQUIRED)'

Information

Communication is only possible on the basis of an agreement between the client and the server regarding the connection encryption.

Solution

To ensure encrypted communciation, set the value to REQUIRED. With the server set to REQUIRED the client must match the encryption for valid communcation to take place. NOTE: failure to specify one of the values will result in an error when an attempt is made to connect to a FIPS 140-1 compliant server.

See Also

https://workbench.cisecurity.org/files/574

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2)

Plugin: Windows

Control ID: 5db21981bd285732ea49a75633fc6f07ca415a5a29601aacd90747a3f7a7ba20