FGFW-ND-000195 - The FortiGate device must use DoD-approved Certificate Authorities (CAs) for public key certificates.

Information

For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this CA will suffice.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. Obtain CA certificate from a DoD-approved provider.
2. Log in to the FortiGate GUI with Super-Admin privilege.
3. Click System.
4. Click Certificates.
5. Click Import in the toolbar.
6. Click CA Certificate.
7. On the Import CA Certificate page, select Type File.
8. Locate the certificate file and upload the certificate file.
9. Click OK to import the certificate.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_FN_FortiGate_Firewall_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-6b., 800-53|SC-17, CAT|II, CCI|CCI-000366, CCI|CCI-001159, Rule-ID|SV-234198r879887_rule, STIG-ID|FGFW-ND-000195, Vuln-ID|V-234198

Plugin: FortiGate

Control ID: a83a2bce018d9cef00e56fa2160ddc686210704f704a39febae051898666f779