WN11-PK-000005 - The DOD Root CA certificates must be installed in the Trusted Root Store.

Information

To ensure secure DOD websites and DOD-signed code are properly validated, the system must trust the DOD Root Certificate Authorities (CAs). The DOD root certificates will ensure that the trust chain is established for server certificates issued from the DOD CAs.

Solution

Install valid (unexpired) DOD Root CA certificates.

The list below is not to be treated as exhaustive. They are valid as of this writing, but the STIG should not be used as a definitive resource for the organizationally approved DOD Root CA certificates for the systems.

DoD Root CA 3
DoD Root CA 5
DoD Root CA 6

The InstallRoot tool is available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. PKI can be found at https://crl.gds.disa.mil/.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_11_V2R8_STIG.zip