DTOO320 - Check e-mail addresses against addresses of certificates being used must be disallowed.

Information

This policy setting controls whether Outlook verifies the user's e-mail address with the address associated with the certificate used for signing. If you enable this policy setting, users can send messages signed with certificates that do not match their e-mail addresses. If you disable or do not configure this policy setting, Outlook verifies that the user's e-mail address matches the certificate being used for signing.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2016 -> Security -> Cryptography 'Do not check e-mail address against address of certificates being used' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Outlook_2016_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-228476r508021_rule, STIG-ID|DTOO320, STIG-Legacy|SV-85901, STIG-Legacy|V-71277, Vuln-ID|V-228476

Plugin: Windows

Control ID: 9c8a382391d46f90b39936c6cbc3822b1bc35f740b2b74e2f1ed7e7c48018958