FFOX-00-000016 - Firefox must have the DOD root certificates installed.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The DOD root certificates will ensure that the trust chain is established for server certificates issued from the DOD Certificate Authority (CA).

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install the DOD root certificates. Other AO-approved certificates may also be used. Certificates designed for SIPRNet may be used as appropriate.

On Windows, import certificates from the operating system by using Certificates >> Import Enterprise Roots (Certificates) via policy or Group Policy Object (GPO).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MOZ_Firefox_V6R6_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000185, Rule-ID|SV-251560r1067559_rule, STIG-ID|FFOX-00-000016, Vuln-ID|V-251560

Plugin: Unix

Control ID: 0f52d63df52c088639d0d57cd51973625a7b4e020ac6fd9fdc5b90f9bdc36e32