WG355 IIS6 - A private web site must utilize certificates from a trusted DoD CA.

Information

The use of a DoD PKI certificate ensures clients that the private web site they are connecting to is legitimate, and is an essential part of the DoD defense-in-depth strategy.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the certificate trust list to trust only DoD-approved PKIs (e.g., DoD PKI, DoD ECA, and DoD-approved external partners).

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-14206r1_rule, STIG-ID|WG355_IIS6, Vuln-ID|V-13620

Plugin: Windows

Control ID: c35b4e5547f352b5e3b80687a20aab1aa76f9dbe89d5dee7598e34cfe253ab98