1.175 WN19-DC-000300

Information

Windows Server 2019 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).

GROUP ID:V-205647
RULE ID:SV-205647r958448

A PKI implementation depends on the practices established by the Certificate Authority (CA) to ensure the implementation is secure. Without proper practices, the certificates issued by a CA have limited value in authentication functions.

Solution

Map user accounts to PKI certificates using the appropriate User Principal Name (UPN) for the network. See PKE documentation for details.

See Also

https://workbench.cisecurity.org/benchmarks/22176

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23(5)

Plugin: Windows

Control ID: 0a0c9843d99f5af89f96c2e16df0e8df08c4d55165008ce3128070d4e322ec75