2.5.14.2.1.3 (L1) Ensure 'Missing Root Certificates' is set to 'Enabled: Error'

Information

This policy setting controls how Outlook functions when a root certificate is missing. Outlook will display either an error or warning based on the status of the root certificate.

The recommended state for this setting is: Enabled: Error

When Outlook accesses a certificate, it validates that it can trust the certificate by examining the root certificate of the issuing CA. If the root certificate can be trusted, then certificates issued by the CA can also be trusted. If Outlook cannot find the root certificate, it cannot validate that any certificates issued by that CA can be trusted. An attacker may compromise a root certificate and then remove the certificate in an attempt to conceal the attack.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Error :

Microsoft Outlook 2016\Security\Cryptography\Signature Status dialog box\Missing root certificates

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a)

Plugin: Windows

Control ID: 0ce11fa5720a90949380f7d1fe9e0f05250620378365f20832bcc43e43dcd7df