WG355 A22 - A private web server's list of CAs in a trust hierarchy must lead to an authorized DoD PKI Root CA.

Information

A PKI certificate is a digital identifier that establishes the identity of an individual or a platform. A server that has a certificate provides users with third-party confirmation of authenticity. Most web browsers perform server authentication automatically and the user is notified only if the authentication fails. The authentication process between the server and the client is performed using the SSL/TLS protocol. Digital certificates are authenticated, issued, and managed by a trusted Certificate Authority (CA).

The use of a trusted certificate validation hierarchy is crucial to the ability to control access to a site's server and to prevent unauthorized access. Only DoD-approved PKIs will be utilized.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the web server's trust store to trust only DoD-approved PKIs (e.g., DoD PKI, DoD ECA, and DoD-approved external partners).

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_UNIX_V1R11_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-32936r1_rule, STIG-ID|WG355_A22, Vuln-ID|V-13620

Plugin: Unix

Control ID: 05531b80be29ca8d9330d964fd064b709160791283500c36f68c71308492a8c9