1.185 WN10-PK-000020

Information

The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.

GROUP ID: V-220906RULE ID: SV-220906r1081051

To ensure users do not experience denial of service when performing certificate-based authentication to DOD websites due to the system chaining to a root other than DOD Root CAs, the US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificate Store. This requirement only applies to unclassified systems.

Solution

Install the US DOD CCEB Interoperability Root CA cross-certificate on unclassified systems.

Issued To - Issued By - ThumbprintDOD Root CA 3 - US DOD CCEB Interoperability Root CA 2 9B74964506C7ED9138070D08D5F8B969866560C8Issued To: DOD Root CA 6Issued By: US DOD CCEB Interoperability Root CA 2Thumbprint: D471CA32F7A692CE6CBB6196BD3377FE4DBCD106NotAfter: 7/18/2026

The certificates can be installed using the InstallRoot tool. The tool and user guide are available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files . PKI can be found at https://crl.gds.disa.mil/ .

See Also

https://workbench.cisecurity.org/benchmarks/23869

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23(5)

Plugin: Windows

Control ID: 91791e9a51416ad6db137f88a1ffb6e24f7a4d76c1343b2f4f1b1dbbf2d742c6