WN22-DC-000300 - Windows Server 2022 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).

Information

A PKI implementation depends on the practices established by the Certificate Authority (CA) to ensure the implementation is secure. Without proper practices, the certificates issued by a CA have limited value in authentication functions.

Satisfies: SRG-OS-000066-GPOS-00034, SRG-OS-000403-GPOS-00182

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Map user accounts to PKI certificates using the appropriate User Principal Name (UPN) for the network. See PKE documentation for details.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2022_V1R4_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)(a), CAT|I, CCI|CCI-000185, Rule-ID|SV-254414r849058_rule, STIG-ID|WN22-DC-000300, Vuln-ID|V-254414

Plugin: Windows

Control ID: 1f6775d8be1ae0a53c768294383f3fcd93c6ef21098df50f71396c39198ca4c9