Skip to main content

💼 Cryptographic Configuration

  • ID: /frameworks/cloudaware/secret-and-certificate-governance/cryptographic-configuration

Description

Policies that identify weak cryptographic configuration for keys, certificates, TLS versions, and cipher suites.

Similar

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (18)

PolicyLogic CountFlagsCompliance
🛡️ AWS ACM Certificate validation has failed🟢1🟢 x6no data
🛡️ AWS ACM Certificate with Wildcard Domain Name🟢1🟢 x6no data
🛡️ AWS ACM RSA Certificate key length is less than 2048 bits🟢1🟢 x6no data
🛡️ AWS API Gateway REST API Stage is not configured to use an SSL certificate for authentication🟢1🟢 x6no data
🛡️ AWS CloudFront Web Distribution uses default SSL/TLS certificate🟢1🟢 x6no data
🛡️ AWS CloudFront Web Distribution uses legacy Security Policy🟢1🟢 x6no data
🛡️ AWS CloudFront Web Distribution uses outdated SSL protocols with Custom Origins🟢1🟢 x6no data
🛡️ AWS ELB Load Balancer listener is configured with an outdated security policy🟢1🟢 x6no data
🛡️ AWS OpenSearch Domain is not encrypted with the latest TLS policy🟢1🟢 x6no data
🛡️ Azure App Service Minimum TLS Version is not set to TLS 1.2 or higher🟢1🟢 x6no data
🛡️ Azure Application Gateway Min SSL protocol version is not TLSv1_2🟢1🟢 x6no data
🛡️ Azure MySQL Flexible Server TLS Version is not set to TLS 1.2🟢1🟢 x6no data
🛡️ Azure Storage Account Minimum TLS Version is not set to TLS 1.2 or higher🟢1🟢 x6no data
🛡️ Azure Storage File Shares SMB Protocol Version is not set to SMB 3.1.1 or higher🟢1🟢 x6no data
🛡️ Google Cloud DNS Managed Zone DNSSEC is not enabled🟢1🟢 x6no data
🛡️ Google Cloud DNS Managed Zone DNSSEC Key-Signing Algorithm is RSASHA1🟢1🟢 x6no data
🛡️ Google Cloud DNS Managed Zone DNSSEC Zone-Signing Algorithm is RSASHA1🟢1🟢 x6no data
🛡️ Google HTTPS or SSL Proxy Load Balancer permits SSL policies with weak cipher suites🟢⚪🟢 x2, ⚪ x1no data