DTBI018 - Check for publishers certificate revocation must be enforced.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Check for publisher's certificate revocation options should be enforced to ensure all PKI signed objects are validated.

Solution

Open Internet Explorer. From the menu bar, select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the 'Advanced' tab from the Advanced tab window, scroll down to the Security category, and select the 'Check for publisher's certificate revocation' box.

Note- Manual entry in the registry key- HKCU\Software\Microsoft\Windows\Current Version\WinTrust\Trust Providers\Software Publishing for the value 'State', set to REG_DWORD = 23C00, may first be required.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IE10_V1R16_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2), CAT|III, Rule-ID|SV-45116r4_rule, STIG-ID|DTBI018, Vuln-ID|V-32808

Plugin: Windows

Control ID: 511af13417ed275f26a8db397d726e64ab36a966a36cad084c00374cd68f6783