WN11-00-000130 - Software certificate installation files must be removed from Windows 11.

Information

Use of software certificates and their accompanying installation files for end users to access resources is less secure than the use of hardware-based certificates.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remove any certificate installation files (*.p12 and *.pfx) found on a system.

Note: This does not apply to server-based applications that have a requirement for .p12 certificate files (e.g., Oracle Wallet Manager) or Adobe PreFlight certificate files.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_11_V1R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-253280r828924_rule, STIG-ID|WN11-00-000130, Vuln-ID|V-253280

Plugin: Windows

Control ID: 26b0b7c6ee7a3ac3e634721d235e8c28b78d8380fa30a60b720ca936b046f29a