| STIG ID | Version | Title | Product |
|---|---|---|---|
| SRG-APP-000224-API-000475 | V1R1 | The API keys must be securely generated using a FIPS-validated Random Number Generator (RNG). | Security Requirements Guide - API |
| SRG-APP-000224-WSR-000135 | V4R4 | The web server must generate a unique session identifier for each session using a FIPS 140-2 approved random number generator. | Security Requirements Guide - Web Server |
| SRG-APP-000224-WSR-000136 | V4R4 | The web server must generate unique session identifiers that cannot be reliably reproduced. | Security Requirements Guide - Web Server |
| SRG-APP-000224-WSR-000137 | V4R4 | The web server must generate a session ID long enough that it cannot be guessed through brute force. | Security Requirements Guide - Web Server |
| SRG-APP-000224-WSR-000138 | V4R4 | The web server must generate a session ID using as much of the character set as possible to reduce the risk of brute force. | Security Requirements Guide - Web Server |
| SRG-APP-000224-WSR-000139 | V4R4 | The web server must generate unique session identifiers with definable entropy. | Security Requirements Guide - Web Server |