ND-iTC / Documents

ND iTC Document repository (NDcPP, ND SD, and all related files)
MIT License
8 stars 1 forks source link

[SD ENHANCEMENT] Add testing for FPT_APW_EXT.1 #254

Open dundiddat opened 1 year ago

dundiddat commented 1 year ago

Provide the location of the issue Section 4.4.1 FPT_APW_EXT.1 Protection of Administrator Passwords

What is the enhancement request for the cPP? Please describe. FPT_APW_EXT.1 does not have a Test AA. A common implementation/nonconformity is storing administrative passwords in cleartext as part of the configuration file. Please introduce a test asking to verify that administrative passwords are not stored in cleartext in the configuration file.

Describe the solution you'd like As stated in the comment.