WG350 A22 - A private web server will have a valid DoD server certificate.

Information

This check verifies that DoD is a hosted web site's CA. The certificate is actually a DoD-issued server certificate used by the organization being reviewed. This is used to verify the authenticity of the web site to the user. If the certificate is not for the server (Certificate belongs to), if the certificate is not issued by DoD (Certificate was issued by), or if the current date is not included in the valid date (Certificate is valid from), then there is no assurance that the use of the certificate is valid. The entire purpose of using a certificate is, therefore, compromised.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the private web site to use a valid DoD certificate.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_UNIX_V1R11_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, Rule-ID|SV-33031r1_rule, STIG-ID|WG350_A22, Vuln-ID|V-2263

Plugin: Unix

Control ID: c3261c6758cf1cc2efc6e9b0e2dd52c6ef63c120906dc95fce32d5cb2c71f55b